ZeroHour

CVE-2022-51012

large

Denial-of-Service Flaw in PocketMine-MP via Malformed NBT Packets

CVSS 4.0
7.1 high
EPSS
<1%p42
Published
()
Modified
AI analysis

PocketMine-MP, a widely used open-source server implementation for Minecraft: Bedrock Edition, fails to properly validate NBT data types when deserializing inventory transaction packets sent by clients. A player with an account on the server (low privileges, no user interaction required) can send a crafted inventory transaction containing malformed NBT tags, causing the server process to crash. The attacker gains denial of service only, with no confidentiality or integrity impact per the CVSS scoring, but a single malicious client can repeatedly crash the affected server. Any operator running PocketMine-MP before version 4.2.9 is affected, with public servers that accept arbitrary players most exposed. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.

What to do: Upgrade PocketMine-MP to version 4.2.9 or later. Until patched, restrict access to trusted players (e.g., via whitelisting), since any authenticated client can crash the server, and monitor public servers for unexplained crashes or restarts. No public exploit is known and EPSS is low, but internet-facing servers should patch promptly because the attack requires only a logged-in player.

Affected
PocketMine-MP Project (open source) PocketMine-MPAll versions prior to 4.2.9 (fixed in 4.2.9)
Estimated exposure
largeon the order of tens of thousands of server deployments worldwide (est.; no authoritative install counts) — PocketMine-MP is one of the most widely deployed third-party server platforms for Minecraft: Pocket/Bedrock Edition, with thousands of publicly listed servers plus an unknown long tail of private and community deployments; no official…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.

Weakness
CWE-20
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.