Impact
A malicious AMQP server can send an undersized HEADER or METHOD frame during client login, causing an unsigned size_t underflow in rabbitmq-c’s amqp_handle_input() function. The parser subtracts the fixed frame header and footer sizes from the target size without verifying the minimum frame length, leading to an out‑of‑bounds read in amqp_decode_table_internal(). The resulting process crash manifests as a denial of service. No reliable memory disclosure or code execution has been demonstrated, so the impact is limited to service interruption.
Affected Systems
The vulnerability exists in versions of the rabbitmq-c client library before v0.16.0 distributed by alanxz. All releases prior to v0.16.0 are affected, and the issue is fixed in v0.16.0.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker on the network path can trigger the denial of service by sending a specially crafted undersized frame to a client that is connecting or already authenticated, provided the AMQP traffic is not protected by TLS with proper certificate validation. No additional privileged access on the client side is required.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN