Skip to content

Denial of Service in polls

High
calzoneman published GHSA-22mq-h58p-q4qv Aug 3, 2021

Package

CyTube

Affected versions

<3.78.0

Patched versions

3.78.0

Description

Impact

Under certain conditions, the poll module could cause a denial of service in which the process consumes 100% CPU and becomes unresponsive. This flaw was discovered during unrelated refactoring; the commit refactoring poll support also coincidentally corrects the flaw.

Further details are witheld to prevent exploitation of active servers running older versions.

Patches

Server owners should upgrade to 3.78.0 or cherry-pick commit f84892d.

Workarounds

N/A

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs