Executive brief
PocketMine-MP is a Minecraft server implementation that manages player inventories and item synchronization. An attacker can send mismatch inventory transaction requests without rate-limiting, forcing the server to send large amounts of serialized inventory data repeatedly, consuming significant bandwidth and potentially degrading server performance for legitimate players.
Technical details
PocketMine-MP fails to rate-limit "mismatch" type InventoryTransactionPacket requests, which are used by clients to request a resync of all open inventories. An attacker with network access and low privileges (ability to connect as a player) can send numerous mismatch transactions per tick, causing the server to synchronize and transmit large amounts of serialized inventory data repeatedly. Since network-serialized inventory items can be very large (especially with NBT data), this acts as a bandwidth amplification attack. The vulnerability was patched in version 4.18.0-ALPHA2 by deferring inventory synchronization until the end of the tick and implementing the ItemStackRequest system.
Affected products
- PocketMine PocketMine-MP before 4.18.0-ALPHA2
Timeline
- 2023-05-30: disclosed
- 2023-03-20: patched: Fix commit ca6d514 merged; patch released in version 4.18.0-ALPHA2
- 2023-05-30: advisory: GHSA-42qm-8v8m-m78c published