Executive brief
PocketMine-MP, a popular server software for Minecraft: Bedrock Edition, contains a flaw in how it handles player inventory actions. An authenticated player can intentionally trigger a server crash by requesting to drop more items than they actually possess in their inventory. This results in a denial-of-service, making the game server unavailable to all other players.
Technical details
An improper input validation vulnerability (CWE-1284) exists in PocketMine-MP's InGamePacketHandler. The flaw was introduced during a revamp of inventory network handling in version 4.18.0. A remote attacker with a valid player session can send a crafted inventory transaction request to drop a quantity of items exceeding what is available in their hotbar. The server fails to validate this quantity against the actual slot count, leading to an unhandled exception and subsequent process crash. The issue is resolved in version 4.18.1 by adding a check in handleNormalTransaction to ensure the dropped count does not exceed the source slot's item count.
Affected products
- pmmp PocketMine-MP < 4.18.1
Timeline
- 2023-05-30: advisory: GitHub Advisory GHSA-h87r-f4vc-mchv published
- 2023-05-30: patched: Fixed in version 4.18.1 via commit 5897476
- 2025-12-31: disclosed: CVE-2023-7332 published to NVD
References
- https://github.com/pmmp/PocketMine-MP/blob/4.18.1/changelogs/4.18.md
- https://github.com/pmmp/PocketMine-MP/commit/5897476
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-h87r-f4vc-mchv
- https://www.vulncheck.com/advisories/pocketmine-mp-improper-validation-of-dropped-item-count-allows-remote-server-crash