GHSA-35mr-4567-66vg
### Affected file * `dulwich/pack.py` (Method: `Pack.resolve_object`) ### Description / Summary A High-severity Denial of Service (DoS) vulnerability exists in the `Pack.resolve_object` method. When resolving an `OFS_DELTA` object, the resolver calculates the base offset using `base_offset = obj_offset - delta_offset`. If a malicious packfile contains an `OFS_DELTA` object where `delta_offset` is `0`, the calculation `obj_offset - 0` resolves back to the current object's own offset. Because the implementation lacks a depth counter, a "visited" set, or an explicit rejection of `delta_offset == 0`, the resolver enters an infinite recursive loop, exhausting CPU resources and eventually crashing the process. **Vulnerable Code Breakdown (`dulwich/pack.py`):** ```python elif obj_type == OFS_DELTA: delta_offset = parse_pack_object_offset_at(...) base_offset = obj_offset - delta_offset # VULNERABILITY: Self-reference if delta_offset == 0 base_type, base_data = self.resolve_object(...) # VULNERABILITY: Infinite recursion ``` ### Potential impact An attacker can trigger this infinite loop via any operation that walks packfiles (e.g., `dulwich clone`, `fetch`, `cat-file`, or internal `Pack.__getitem__` lookups). 1. **CPU Exhaustion:** The process will spin at 100% CPU indefinitely. 2. **Denial of Service:** Any service using `dulwich` (web interfaces, CI/CD runners) will hang or crash, preventing legitimate repository access. 3. **Protocol Incompatibility:** This behavior violates the Git packfile specification. The standard `git` C client explicitly guards against this: `if (!base_offset) die("delta offset == 0 is invalid");`. ### POC (Proof of Concept) The following Python script generates a 44-byte packfile that triggers the loop: ```python from dulwich.pack import Pack import struct, zlib, tempfile, os # Build a single OFS_DELTA entry whose delta_offset is 0 type_ofs_delta = 6 header = bytes([(type_ofs_delta << 4) | 0]) ofs_bytes = bytes([0x
Properties
- severity
- medium
- summary
- Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution
- cvss_score
- 6.5
- retrieved_at
- 2026-10-03T18:15:00+00:00
- ghsa_published
- 2026-10-02T18:54:39Z
- source_url
- https://github.com/advisories/GHSA-35mr-4567-66vg
- ghsa_updated
- 2026-10-02T18:54:40Z
- ghsa_id
- GHSA-35mr-4567-66vg
- last_source
- GitHub Advisory Database
- cve_id
- GHSA-35mr-4567-66vg
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- signal_observed_at
- 2026-10-02T19:33:52+00:00
- is_ghsa_only
- true
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph