Executive brief
A vulnerability in the react-native-reanimated library, which is used to create smooth animations in mobile applications, could allow an attacker to crash an app or make it unresponsive. By providing a specially crafted color string, an attacker can trigger a process that consumes excessive CPU resources. This results in a denial-of-service condition, affecting the application's availability for users.
Technical details
The react-native-reanimated library before versions 2.10.0 and 3.0.0-rc.1 contains a Regular Expression Denial of Service (ReDoS) vulnerability. The flaw exists in the `Colors.js` component due to an inefficient regular expression used to parse numeric values within color strings. An attacker who can control the color input passed to the library can provide a maliciously crafted string that triggers catastrophic backtracking in the regex engine. This leads to 100% CPU utilization and a denial-of-service (DoS) condition. The issue was resolved by optimizing the regular expression to ensure linear processing time.
Affected products
- software-mansion react-native-reanimated < 2.10.0, < 3.0.0-rc.1
Timeline
- 2022-07-12: disclosed: Initial pull request describing the ReDoS vulnerability submitted.
- 2022-07-25: patched: Fix merged into the main branch.
- 2022-09-30: advisory: NVD publication date.
- 2022-10-01: advisory: GitHub Advisory published.
References
- https://github.com/software-mansion/react-native-reanimated/pull/3382
- https://github.com/software-mansion/react-native-reanimated/pull/3382/commits/7adf06d0c59382d884a04be86a96eede3d0432fa
- https://github.com/software-mansion/react-native-reanimated/commit/8a927904366fa2d02df7a11553f8b0aa93471279
- https://github.com/software-mansion/react-native-reanimated
- https://github.com/software-mansion/react-native-reanimated/compare/2.9.1...2.10.0
- https://github.com/software-mansion/react-native-reanimated/releases/tag/3.0.0-rc.1