https://bz.apache.org/bugzilla/show_bug.cgi?id=70255

            Bug ID: 70255
           Summary: mod_proxy_beacon: pre-auth per-tick memory
                    amplification via UDP flood (missing per-datagram
                    subpool)
           Product: Apache httpd-2
           Version: 2.5-HEAD
          Hardware: PC
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P2
         Component: mod_proxy
          Assignee: [email protected]
          Reporter: [email protected]
  Target Milestone: ---

Created attachment 40221
  --> https://bz.apache.org/bugzilla/attachment.cgi?id=40221&action=edit
proposed patch

mod_proxy_beacon's watchdog callback drains the UDP socket in an unbounded
for(;;) loop (line 1077) and calls ap_escape_logitem(pool, msg_str) for every
datagram BEFORE beacon_verify() runs (line 1127). This allocates from the
shared watchdog temp_pool, which is only cleared after the callback returns
(mod_watchdog.c:194).

Under a UDP flood (~233K pkt/s of max-size 2048-byte datagrams), the per-tick
pool accumulates ~44MB of allocations (from a 4.7MB baseline) and the beacon
watchdog thread is pinned at 100% CPU. No shared secret is required since the
allocation precedes the MAC check.

The module's own comments cite mod_heartmonitor as its model. mod_heartmonitor
avoids this by using a per-datagram subpool (apr_pool_create/apr_pool_destroy
each iteration at lines 636/656 of mod_heartmonitor.c) and a time-bounded
receive loop (while ((now - cur) < interval)). mod_proxy_beacon dropped both
defenses.

Attached patch adds a per-datagram subpool following the mod_heartmonitor
pattern:
- apr_pool_create() at the top of each loop iteration
- ap_escape_logitem() and beacon_handle_announce() allocate from the
per-datagram pool
- apr_pool_destroy() on every exit path (break, continue, end of iteration)

This bounds per-tick memory to a single datagram's allocations at any time,
regardless of flood rate.

Lab tested in Docker (httpd trunk 2.5.1-dev, Debian bookworm, commit f4ec94c).
PoC: simple UDP flooder sending to the ProxyBeaconListen port.

I note this module is experimental and trunk-only (not in any 2.4.x release).
Filing here per guidance from [email protected] (Piotr P. Karwasz).

--- Attach ---
mod_proxy_beacon-subpool.patch

-- 
You are receiving this mail because:
You are the assignee for the bug.
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to