Executive brief
PocketMine-MP is a popular Minecraft Bedrock Edition server software. A validation flaw allows attackers to send malformed tool and armor item data with negative or out-of-range damage values, causing the server to crash. This availability impact affects game operations and player experience.
Technical details
PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. The vulnerability exists in the TypeConverter class, which blindly uses metadata values from client-sent itemstack NBT without range checking. When an attacker sends negative or out-of-range damage values (outside 0-0x7fff), the Durable class throws an unhandled exception, crashing the server. The attack requires network access and low privileges (ability to send game packets), with no user interaction needed. Patch version 4.2.4 adds explicit range validation in TypeConverter before processing the metadata.
Affected products
- PocketMine PocketMine-MP before 4.2.3
Timeline
- 2022-03-18: disclosed
- 2022: patched: patch version 4.2.4 released