CWE-835
AllowedLoop with Unreachable Exit Condition ('Infinite Loop')
Abstraction: Base · Status: Incomplete
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
1253 vulnerabilities reference this CWE, most recent first.
GHSA-3264-3FM9-FG44
Vulnerability from github – Published: 2021-05-07 15:54 – Updated: 2022-10-07 20:40A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 1.23"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tika:tika"
},
"ranges": [
{
"events": [
{
"introduced": "1.0"
},
{
"fixed": "1.24"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2020-1951"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": true,
"github_reviewed_at": "2021-05-05T22:47:57Z",
"nvd_published_at": "2020-03-23T14:15:00Z",
"severity": "MODERATE"
},
"details": "A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika\u0027s PSDParser in versions 1.0-1.23.",
"id": "GHSA-3264-3fm9-fg44",
"modified": "2022-10-07T20:40:10Z",
"published": "2021-05-07T15:54:00Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-1951"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/tika"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/rd8c1b42bd0e31870d804890b3f00b13d837c528f7ebaf77031323172%40%3Cdev.tika.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2020/03/msg00035.html"
},
{
"type": "WEB",
"url": "https://usn.ubuntu.com/4564-1"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2020.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuoct2020.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Infinite Loop in Apache Tika"
}
GHSA-3274-8H4C-G6Q9
Vulnerability from github – Published: 2022-04-21 01:57 – Updated: 2024-04-03 23:04In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.
{
"affected": [],
"aliases": [
"CVE-2010-0207"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2019-10-30T21:15:00Z",
"severity": "MODERATE"
},
"details": "In xpdf, the xref table contains an infinite loop which allows remote attackers to cause a denial of service (application crash) in xpdf-based PDF viewers.",
"id": "GHSA-3274-8h4c-g6q9",
"modified": "2024-04-03T23:04:23Z",
"published": "2022-04-21T01:57:45Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2010-0207"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2010-0207"
},
{
"type": "WEB",
"url": "https://security-tracker.debian.org/tracker/CVE-2010-0207"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-32JQ-W4J4-WJVC
Vulnerability from github – Published: 2025-01-11 15:30 – Updated: 2025-11-03 21:32In the Linux kernel, the following vulnerability has been resolved:
ceph: give up on paths longer than PATH_MAX
If the full path to be built by ceph_mdsc_build_path() happens to be longer than PATH_MAX, then this function will enter an endless (retry) loop, effectively blocking the whole task. Most of the machine becomes unusable, making this a very simple and effective DoS vulnerability.
I cannot imagine why this retry was ever implemented, but it seems rather useless and harmful to me. Let's remove it and fail with ENAMETOOLONG instead.
{
"affected": [],
"aliases": [
"CVE-2024-53685"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-01-11T13:15:25Z",
"severity": "MODERATE"
},
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nceph: give up on paths longer than PATH_MAX\n\nIf the full path to be built by ceph_mdsc_build_path() happens to be\nlonger than PATH_MAX, then this function will enter an endless (retry)\nloop, effectively blocking the whole task. Most of the machine\nbecomes unusable, making this a very simple and effective DoS\nvulnerability.\n\nI cannot imagine why this retry was ever implemented, but it seems\nrather useless and harmful to me. Let\u0027s remove it and fail with\nENAMETOOLONG instead.",
"id": "GHSA-32jq-w4j4-wjvc",
"modified": "2025-11-03T21:32:07Z",
"published": "2025-01-11T15:30:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-53685"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0f2b2d9e881c90402dbe28f9ba831775b7992e1f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/550f7ca98ee028a606aa75705a7e77b1bd11720f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/99a37ab76a315c8307eb5b0dc095d8ad9d8efeaa"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c47ed91156daf328601d02b58d52d9804da54108"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/d42ad3f161a5a487f81915c406f46943c7187a0a"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/e4b168c64da06954be5d520f6c16469b1cadc069"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-32PX-JFGQ-53XF
Vulnerability from github – Published: 2026-05-11 18:31 – Updated: 2026-07-23 12:31A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.
{
"affected": [],
"aliases": [
"CVE-2026-4890"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-05-11T18:16:41Z",
"severity": "HIGH"
},
"details": "A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.",
"id": "GHSA-32px-jfgq-53xf",
"modified": "2026-07-23T12:31:48Z",
"published": "2026-05-11T18:31:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-4890"
},
{
"type": "WEB",
"url": "https://github.com/NixOS/nixpkgs/pull/519082"
},
{
"type": "WEB",
"url": "https://github.com/NixOS/nixpkgs/pull/519093"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:19158"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:19373"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:20589"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:34508"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:40762"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2026-4890"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2458516"
},
{
"type": "WEB",
"url": "https://github.com/pi-hole/FTL/releases/tag/v6.6.2"
},
{
"type": "WEB",
"url": "https://lists.thekelleys.org.uk/pipermail/dnsmasq-discuss/2026q2/018471.html"
},
{
"type": "WEB",
"url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-4890.json"
},
{
"type": "WEB",
"url": "https://thekelleys.org.uk/dnsmasq"
},
{
"type": "WEB",
"url": "https://thekelleys.org.uk/dnsmasq/CVE"
},
{
"type": "WEB",
"url": "https://www.kb.cert.org/vuls/id/471747"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-333M-Q4JM-QJQ4
Vulnerability from github – Published: 2024-10-21 15:32 – Updated: 2025-11-04 00:31In the Linux kernel, the following vulnerability has been resolved:
x86/sgx: Fix deadlock in SGX NUMA node search
When the current node doesn't have an EPC section configured by firmware and all other EPC sections are used up, CPU can get stuck inside the while loop that looks for an available EPC page from remote nodes indefinitely, leading to a soft lockup. Note how nid_of_current will never be equal to nid in that while loop because nid_of_current is not set in sgx_numa_mask.
Also worth mentioning is that it's perfectly fine for the firmware not to setup an EPC section on a node. While setting up an EPC section on each node can enhance performance, it is not a requirement for functionality.
Rework the loop to start and end on a node that has SGX memory. This avoids the deadlock looking for the current SGX-lacking node to show up in the loop when it never will.
{
"affected": [],
"aliases": [
"CVE-2024-49856"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-10-21T13:15:06Z",
"severity": "MODERATE"
},
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nx86/sgx: Fix deadlock in SGX NUMA node search\n\nWhen the current node doesn\u0027t have an EPC section configured by firmware\nand all other EPC sections are used up, CPU can get stuck inside the\nwhile loop that looks for an available EPC page from remote nodes\nindefinitely, leading to a soft lockup. Note how nid_of_current will\nnever be equal to nid in that while loop because nid_of_current is not\nset in sgx_numa_mask.\n\nAlso worth mentioning is that it\u0027s perfectly fine for the firmware not\nto setup an EPC section on a node. While setting up an EPC section on\neach node can enhance performance, it is not a requirement for\nfunctionality.\n\nRework the loop to start and end on *a* node that has SGX memory. This\navoids the deadlock looking for the current SGX-lacking node to show up\nin the loop when it never will.",
"id": "GHSA-333m-q4jm-qjq4",
"modified": "2025-11-04T00:31:39Z",
"published": "2024-10-21T15:32:27Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-49856"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/0f89fb4042c08fd143bfc28af08bf6c8a0197eea"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/20c96d0aaabfe361fc2a11c173968dc67feadbbf"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/40fb64257dab507d86b5f1f2a62f3669ef0c91a8"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8132510c915815e6b537ab937d94ed66893bc7b8"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/9c936844010466535bd46ea4ce4656ef17653644"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/fb2d057539eda67ec7cfc369bf587e6518a9b99d"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-33M9-4Q46-9Q55
Vulnerability from github – Published: 2026-07-18 15:31 – Updated: 2026-08-13 15:34SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to define custom database functions via DEFINE FUNCTION using nested FOR loops. Although a single loop's iteration count is constrained, nesting multiple loops (e.g., each with 1,000,000 iterations) is not, so an attacker can execute a function that consumes all server CPU time. Configured timeouts do not stop the execution, rendering the server unresponsive to other queries and connections until it is manually restarted.
{
"affected": [],
"aliases": [
"CVE-2025-71397"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-18T14:17:11Z",
"severity": "HIGH"
},
"details": "SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permissions (at the root, namespace, or database level) to define custom database functions via DEFINE FUNCTION using nested FOR loops. Although a single loop\u0027s iteration count is constrained, nesting multiple loops (e.g., each with 1,000,000 iterations) is not, so an attacker can execute a function that consumes all server CPU time. Configured timeouts do not stop the execution, rendering the server unresponsive to other queries and connections until it is manually restarted.",
"id": "GHSA-33m9-4q46-9q55",
"modified": "2026-08-13T15:34:13Z",
"published": "2026-07-18T15:31:49Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/surrealdb/surrealdb/security/advisories/GHSA-pxw4-94j3-v9pf"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-71397"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/surrealdb-before-cpu-exhaustion-via-nested-for-loops"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-3448-VFVV-XP9G
Vulnerability from github – Published: 2018-12-26 17:45 – Updated: 2023-09-27 11:10A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.tika:tika-parsers"
},
"ranges": [
{
"events": [
{
"introduced": "1.8"
},
{
"fixed": "1.20"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2018-17197"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": true,
"github_reviewed_at": "2020-06-16T20:53:58Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika\u0027s SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.",
"id": "GHSA-3448-vfvv-xp9g",
"modified": "2023-09-27T11:10:06Z",
"published": "2018-12-26T17:45:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-17197"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-3448-vfvv-xp9g"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/7c021a4ea2037e52e74628e17e8e0e2acab1f447160edc8be0eae6d3@%3Cdev.tika.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpuapr2020.html"
},
{
"type": "WEB",
"url": "https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/106293"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Apache Tika Denial of Service due to Infinite Loop in Tika\u0027s SQLite3Parser"
}
GHSA-345H-R9M2-JR4P
Vulnerability from github – Published: 2026-07-14 18:31 – Updated: 2026-07-14 18:31In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.
{
"affected": [],
"aliases": [
"CVE-2026-62642"
],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-14T16:17:04Z",
"severity": "MODERATE"
},
"details": "In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, an infinite loop was discovered in the TNEF decoder, which may lead to denial of service upon opening an email with a TNEF attachment.",
"id": "GHSA-345h-r9m2-jr4p",
"modified": "2026-07-14T18:31:56Z",
"published": "2026-07-14T18:31:56Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-62642"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/commit/132ac8dd5a55c8466be12de1daf84355697ffa89"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/commit/877269c79359d959a94f13c9070cab0f3389c193"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/commit/a007321346380136b3de2bd75b486b04f63c0d38"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/commit/fb952956c6eaf29e963f1a718d028d66e7957ce0"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/releases/tag/1.6.17"
},
{
"type": "WEB",
"url": "https://github.com/roundcube/roundcubemail/releases/tag/1.7.2"
},
{
"type": "WEB",
"url": "https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-35MR-4567-66VG
Vulnerability from github – Published: 2026-10-02 18:54 – Updated: 2026-10-02 18:54Affected file
dulwich/pack.py(Method:Pack.resolve_object)
Description / Summary
A High-severity Denial of Service (DoS) vulnerability exists in the Pack.resolve_object method. When resolving an OFS_DELTA object, the resolver calculates the base offset using base_offset = obj_offset - delta_offset.
If a malicious packfile contains an OFS_DELTA object where delta_offset is 0, the calculation obj_offset - 0 resolves back to the current object's own offset. Because the implementation lacks a depth counter, a "visited" set, or an explicit rejection of delta_offset == 0, the resolver enters an infinite recursive loop, exhausting CPU resources and eventually crashing the process.
Vulnerable Code Breakdown (dulwich/pack.py):
elif obj_type == OFS_DELTA:
delta_offset = parse_pack_object_offset_at(...)
base_offset = obj_offset - delta_offset # VULNERABILITY: Self-reference if delta_offset == 0
base_type, base_data = self.resolve_object(...) # VULNERABILITY: Infinite recursion
Potential impact
An attacker can trigger this infinite loop via any operation that walks packfiles (e.g., dulwich clone, fetch, cat-file, or internal Pack.__getitem__ lookups).
- CPU Exhaustion: The process will spin at 100% CPU indefinitely.
- Denial of Service: Any service using
dulwich(web interfaces, CI/CD runners) will hang or crash, preventing legitimate repository access. - Protocol Incompatibility: This behavior violates the Git packfile specification. The standard
gitC client explicitly guards against this:if (!base_offset) die("delta offset == 0 is invalid");.
POC (Proof of Concept)
The following Python script generates a 44-byte packfile that triggers the loop:
from dulwich.pack import Pack
import struct, zlib, tempfile, os
# Build a single OFS_DELTA entry whose delta_offset is 0
type_ofs_delta = 6
header = bytes([(type_ofs_delta << 4) | 0])
ofs_bytes = bytes([0x00]) # delta_offset = 0
body = zlib.compress(b'')
raw = header + ofs_bytes + body
pack = b'PACK' + struct.pack('>I', 2) + struct.pack('>I', 1) + raw + (b'\x00' * 20)
fd, path = tempfile.mkstemp(suffix='.pack')
os.write(fd, pack); os.close(fd)
# Trigger: This call never returns and spins at 100% CPU
p = Pack(path)
obj = p[list(p.iterobjects())[0]]
Possible solution
- Explicit Guard: Add a check in
Pack.resolve_objectto rejectdelta_offset == 0:python if delta_offset == 0: raise CorruptPacksFile("OFS_DELTA has self-referential delta_offset=0") - Recursion Depth: Implement a depth limit (e.g.,
MAX_DELTA_DEPTH = 50) to prevent long, non-looping chains of deltas (OFS or REF).
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "dulwich"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.2.9"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [],
"database_specific": {
"cwe_ids": [
"CWE-835"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-02T18:54:39Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "### Affected file\n* `dulwich/pack.py` (Method: `Pack.resolve_object`)\n\n### Description / Summary\nA High-severity Denial of Service (DoS) vulnerability exists in the `Pack.resolve_object` method. When resolving an `OFS_DELTA` object, the resolver calculates the base offset using `base_offset = obj_offset - delta_offset`.\n\nIf a malicious packfile contains an `OFS_DELTA` object where `delta_offset` is `0`, the calculation `obj_offset - 0` resolves back to the current object\u0027s own offset. Because the implementation lacks a depth counter, a \"visited\" set, or an explicit rejection of `delta_offset == 0`, the resolver enters an infinite recursive loop, exhausting CPU resources and eventually crashing the process.\n\n**Vulnerable Code Breakdown (`dulwich/pack.py`):**\n```python\nelif obj_type == OFS_DELTA:\n delta_offset = parse_pack_object_offset_at(...)\n base_offset = obj_offset - delta_offset # VULNERABILITY: Self-reference if delta_offset == 0\n base_type, base_data = self.resolve_object(...) # VULNERABILITY: Infinite recursion\n```\n\n### Potential impact\n\nAn attacker can trigger this infinite loop via any operation that walks packfiles (e.g., `dulwich clone`, `fetch`, `cat-file`, or internal `Pack.__getitem__` lookups). \n\n1. **CPU Exhaustion:** The process will spin at 100% CPU indefinitely.\n2. **Denial of Service:** Any service using `dulwich` (web interfaces, CI/CD runners) will hang or crash, preventing legitimate repository access.\n3. **Protocol Incompatibility:** This behavior violates the Git packfile specification. The standard `git` C client explicitly guards against this: `if (!base_offset) die(\"delta offset == 0 is invalid\");`.\n\n### POC (Proof of Concept)\nThe following Python script generates a 44-byte packfile that triggers the loop:\n\n```python\nfrom dulwich.pack import Pack\nimport struct, zlib, tempfile, os\n\n# Build a single OFS_DELTA entry whose delta_offset is 0\ntype_ofs_delta = 6\nheader = bytes([(type_ofs_delta \u003c\u003c 4) | 0])\nofs_bytes = bytes([0x00]) # delta_offset = 0\nbody = zlib.compress(b\u0027\u0027)\nraw = header + ofs_bytes + body\n\npack = b\u0027PACK\u0027 + struct.pack(\u0027\u003eI\u0027, 2) + struct.pack(\u0027\u003eI\u0027, 1) + raw + (b\u0027\\x00\u0027 * 20)\n\nfd, path = tempfile.mkstemp(suffix=\u0027.pack\u0027)\nos.write(fd, pack); os.close(fd)\n\n# Trigger: This call never returns and spins at 100% CPU\np = Pack(path)\nobj = p[list(p.iterobjects())[0]]\n```\n\n### Possible solution\n1. **Explicit Guard:** Add a check in `Pack.resolve_object` to reject `delta_offset == 0`:\n ```python\n if delta_offset == 0:\n raise CorruptPacksFile(\"OFS_DELTA has self-referential delta_offset=0\")\n ```\n2. **Recursion Depth:** Implement a depth limit (e.g., `MAX_DELTA_DEPTH = 50`) to prevent long, non-looping chains of deltas (OFS or REF).",
"id": "GHSA-35mr-4567-66vg",
"modified": "2026-10-02T18:54:39Z",
"published": "2026-10-02T18:54:39Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/jelmer/dulwich/security/advisories/GHSA-35mr-4567-66vg"
},
{
"type": "WEB",
"url": "https://github.com/jelmer/dulwich/commit/d06ffc3e1aff0ea0a32094debead891be0083eb7"
},
{
"type": "PACKAGE",
"url": "https://github.com/jelmer/dulwich"
},
{
"type": "WEB",
"url": "https://github.com/jelmer/dulwich/releases/tag/dulwich-1.2.9"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
],
"summary": "Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution"
}
GHSA-35W7-H3V9-8QW4
Vulnerability from github – Published: 2023-10-10 15:30 – Updated: 2025-11-04 21:30A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
{
"affected": [],
"aliases": [
"CVE-2023-43786"
],
"database_specific": {
"cwe_ids": [
"CWE-400",
"CWE-835"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-10-10T13:15:22Z",
"severity": "MODERATE"
},
"details": "A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.",
"id": "GHSA-35w7-h3v9-8qw4",
"modified": "2025-11-04T21:30:43Z",
"published": "2023-10-10T15:30:50Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-43786"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2145"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2024:2973"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-43786"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2242253"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00005.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/63IBRFLQVZSMOAZBZOBKFWJP26ILRAGQ"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231103-0006"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2024/01/24/9"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
No mitigation information available for this CWE.
No CAPEC attack patterns related to this CWE.