CVE-2023-54396
largeUnvalidated dye color IDs in PocketMine-MP banner NBT crash servers (DoS)
PocketMine-MP, a widely used third-party Minecraft Bedrock Edition server platform, fails to validate dye color IDs when deserializing banner NBT data (CWE-129, improper validation of array index). An attacker with player-level access can submit an inventory transaction or command containing an invalid banner color value, causing an undefined-offset error that crashes the server process. The impact is complete loss of availability for the affected server and all connected players; there is no confidentiality or integrity impact and no evidence of data compromise. Any operator running PocketMine-MP prior to version 4.8.1 is affected, and any publicly joinable server can be reached by any authenticated player. As of disclosure there are no known exploits, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.
What to do: Upgrade PocketMine-MP to version 4.8.1 or later. If an immediate upgrade is not possible, remember the attack requires only player-level access, so any joinable server is at risk; restrict who can connect (allowlists) and monitor for crash reports involving banner or NBT deserialization. Check your deployed PocketMine-MP version against the fixed 4.8.1 release.
| PocketMine-MP Project (pmmp) PocketMine-MP | All versions before 4.8.1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.
- Weakness
- CWE-129
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.