Skip to content

gl: uncapped success-body reads let a malicious node exhaust client memory #473

Description

@euxaristia

Summary

Body caps (read_body_capped, the codebase's INV-6 "reads must be bounded") are applied only on error paths (peer.rs, sync.rs, whoami.rs). Success bodies are buffered to completion with no cap: crates/git-remote-gitlawb/src/main.rs:257 (info/refs), :569 (each pack negotiation round), crates/gl/src/clone.rs:327 (resp.json()), :377 (per-envelope bytes), crates/gl/src/mcp.rs:796.

Impact

A hostile node answering a fetch, clone, or MCP call with an oversized 200 body causes full buffering and client memory exhaustion on the most basic operations. A MITM on a plaintext GITLAWB_NODE reaches the same sinks (see #413/#443 for the scheme gap).

Remediation

  1. Apply read_body_capped (or streaming with a hard cap) to success bodies on the refs, pack, clone, and MCP paths.

Proposed labels: kind:security, crate:gl, crate:git-remote.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    crate:git-remotegit-remote-gitlawb — the git remote helpercrate:glgl — the contributor CLIkind:securityVulnerability fix or hardeningsev:mediumDegraded but workaround exists

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions