ZeroHour

CVE-2023-54396

large

Unvalidated dye color IDs in PocketMine-MP banner NBT crash servers (DoS)

CVSS 4.0
7.1 high
EPSS
<1%p31
Published
()
Modified
AI analysis

PocketMine-MP, a widely used third-party Minecraft Bedrock Edition server platform, fails to validate dye color IDs when deserializing banner NBT data (CWE-129, improper validation of array index). An attacker with player-level access can submit an inventory transaction or command containing an invalid banner color value, causing an undefined-offset error that crashes the server process. The impact is complete loss of availability for the affected server and all connected players; there is no confidentiality or integrity impact and no evidence of data compromise. Any operator running PocketMine-MP prior to version 4.8.1 is affected, and any publicly joinable server can be reached by any authenticated player. As of disclosure there are no known exploits, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.

What to do: Upgrade PocketMine-MP to version 4.8.1 or later. If an immediate upgrade is not possible, remember the attack requires only player-level access, so any joinable server is at risk; restrict who can connect (allowlists) and monitor for crash reports involving banner or NBT deserialization. Check your deployed PocketMine-MP version against the fixed 4.8.1 release.

Affected
PocketMine-MP Project (pmmp) PocketMine-MPAll versions before 4.8.1
Estimated exposure
largetens of thousands of community-run Bedrock server deployments — PocketMine-MP is the most widely deployed third-party Minecraft Bedrock server platform, and public server-list scans plus the project's large open-source user base indicate thousands of listed public servers and an order of magnitude more…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.

Weakness
CWE-129
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.