ppkarwasz opened a new pull request, #4272:
URL: https://github.com/apache/logging-log4j2/pull/4272

   > [!IMPORTANT]
   > This PR is part of the deserialization hardening work tracked in #4168. 
The Logging Services PMC does **not** use nor recommend Java 
serialization/deserialization, and [our security 
FAQ](https://logging.apache.org/security/faq.html#deserialization) has long 
documented this position. This work is submitted solely to reduce the 
false-positive "vulnerability" reports that keep being filed regardless of that 
FAQ. Its utility for end users is close to zero.
   
   `SortedArrayStringMap.readObject` allocated its key and value arrays at the 
capacity declared in the stream before reading a single entry, so a forged 
capacity field caused an arbitrarily large allocation (`OutOfMemoryError`) — 
the classic serialization memory-amplification shape, where a few bytes of 
input commit the reader to megabytes of allocation.
   
   The declared capacity is no longer trusted: deserialization pre-allocates at 
most 128 Ki entries (1 MiB per array on a typical 64-bit JVM) and grows the 
arrays as entries are actually read, so allocation is proportional to the data 
present in the stream. A `mappings` count exceeding the declared capacity is 
now rejected as an inconsistent stream.
   
   The serialized form is unchanged — this only affects how a stream is read — 
so there is no compatibility impact in either direction.
   
   Stacked on #4271.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to