-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the OFPGroupDescStats parser's handling of bucket lengths. The code shown in GitHub issue #193 demonstrates a while loop that parses OFPBucket entries until accumulated length matches stats.length. When a malicious bucket with len=0 is processed, the loop variables never increment, creating an infinite loop. This matches the CVE description of DoS via OFPBucket.len=0. The code structure and vulnerability mechanism are clearly identified in the provided references.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| ryu | pip | <= 4.34 |
Ongoing coverage of React2Shell