Executive brief
rabbitmq-c is a C library used by applications to communicate with RabbitMQ message brokers. A malicious or compromised AMQP server can crash a client application during login by sending crafted frames with incorrect size values, triggering an out-of-bounds memory read. This denial-of-service attack requires network access to the AMQP server and can be exploited over unencrypted connections.
Technical details
The vulnerability is an unsigned integer underflow (CWE-191) in the amqp_handle_input() function within librabbitmq/amqp_connection.c. When parsing AMQP frames, the parser computes the encoded payload size by subtracting fixed header, per-frame-type fields, and footer sizes from a server-supplied target_size without first validating that target_size meets the minimum required frame length. Because encoded.len is a size_t, this subtraction wraps to a value near SIZE_MAX when the frame is undersized. The wrapped value is then passed through amqp_decode_properties() to amqp_decode_table_internal(), defeating internal bounds checks and causing an out-of-bounds read and process crash during the AMQP login handshake. An on-path attacker on an unencrypted connection can also trigger this. The vulnerability is fixed in version 0.16.0 by validating target_size against minimum frame lengths before computing encoded.len.
Affected products
- alanxz rabbitmq-c before 0.16.0
Timeline
- 2026-09-17: disclosed
- 2026-06-08: patched: Fix merged in version 0.16.0