Impact
rabbitmq-c, a C-language AMQP client library, has a heap buffer overflow in the AMQP login handshake. During amqp_login(), an attacker can send an undersized connection.tune.frame_max value. The library accepts this value and later reallocates the outbound buffer without enforcing AMQP_FRAME_MIN_SIZE. When the connection.tune-ok frame is serialized, the client writes beyond the undersized heap allocation, corrupting memory. This leads to a denial of service and could potentially allow code execution, although no exploit has been demonstrated.
Affected Systems
The vulnerability affects the rabbitmq-c library produced by alanxz. All releases older than 0.16.0 are vulnerable. The fix is included in version 0.16.0; upgrading eliminates the overflow. No specific operating system or distribution is mentioned in the data, so any platform using the affected library is at risk.
Risk and Exploitability
The CVSS score of 7.1 marks the issue as high severity, and the EPSS score of less than 1% implies a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring a client to initiate a connection with a malicious or compromised AMQP server. For plaintext AMQP traffic, an on-path attacker could trigger the flaw. Successful exploitation would result in memory corruption and likely a service crash; theoretical code execution could occur if the client runs with elevated privileges. Given the high CVSS and the lack of a public exploit, timely patching is advised.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN