ppkarwasz opened a new pull request, #4272: URL: https://github.com/apache/logging-log4j2/pull/4272
> [!IMPORTANT] > This PR is part of the deserialization hardening work tracked in #4168. The Logging Services PMC does **not** use nor recommend Java serialization/deserialization, and [our security FAQ](https://logging.apache.org/security/faq.html#deserialization) has long documented this position. This work is submitted solely to reduce the false-positive "vulnerability" reports that keep being filed regardless of that FAQ. Its utility for end users is close to zero. `SortedArrayStringMap.readObject` allocated its key and value arrays at the capacity declared in the stream before reading a single entry, so a forged capacity field caused an arbitrarily large allocation (`OutOfMemoryError`) — the classic serialization memory-amplification shape, where a few bytes of input commit the reader to megabytes of allocation. The declared capacity is no longer trusted: deserialization pre-allocates at most 128 Ki entries (1 MiB per array on a typical 64-bit JVM) and grows the arrays as entries are actually read, so allocation is proportional to the data present in the stream. A `mappings` count exceeding the declared capacity is now rejected as an inconsistent stream. The serialized form is unchanged — this only affects how a stream is read — so there is no compatibility impact in either direction. Stacked on #4271. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
