Executive brief
Synology DiskStation Manager (DSM) is a central operating system for Synology NAS devices that manages storage, files, and user access. A flaw in the File Operation component allows authenticated users to trigger a denial-of-service condition, potentially causing service interruptions for all users accessing the NAS.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in the File Operation component of Synology DSM. The vulnerability requires remote network access and valid user authentication credentials; no special privileges or user interaction is needed. An authenticated attacker can trigger limited denial-of-service attacks by exploiting the integer overflow. Patches are available: DSM 7.2.1-69057-10, DSM 7.2.2-72806-7, and DSM 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager (DSM) before 7.2.1-69057-10, before 7.2.2-72806-7, before 7.3.2-86009-2
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Patches released for DSM 7.2.1, 7.2.2, and 7.3
- 2026-09-18: advisory