Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a vulnerability in DRPC servers that can lead to the exhaustion of server memory by retaining an unbounded number of function names. Exploitation of this issue requires no authentication and can be performed remotely, potentially causing service disruption. The primary concern is to confirm if your environment utilizes DRPC servers and assess their exposure.
- Unauthenticated remote attackers can cause memory exhaustion.
- Important for DRPC servers to prevent denial-of-service.
- Verify DRPC usage and network exposure.
Attack Path
How an attacker could exploit the issue
An attacker can target a DRPC server by sending a continuous stream of unique function names. Because the server does not remove entries for these names from its internal map, it will eventually exhaust its available memory, leading to a denial of service.
- No authentication required for access.
- Triggered by unique, unconstrained function names.
- Leads to server memory exhaustion and denial of service.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could affect the memory of a DRPC server, potentially leading to service disruption. It occurs when a client sends a high volume of unique function names to the server, causing it to retain an ever-growing amount of data related to these names. This issue is exacerbated because the DRPC server's `drpc.authorizer` is unset by default, meaning no authentication is required to reach the endpoint.
- Server memory.
- Unique client-sent function names.
- Denial of service.
Operational Fix
Recommended remediation, mitigation, and detection steps
The DRPC server's susceptibility to unbounded memory exhaustion due to uncleaned function name entries requires immediate attention from the platform or infrastructure team responsible for its deployment. The first practical step is to identify all instances of the DRPC server, confirm their network accessibility and business criticality, and then assign an accountable owner to coordinate remediation.
- Platform/Infrastructure team owns remediation.
- Verify DRPC server reachability and criticality.
- Plan and coordinate upgrade or configuration changes.