天下漏洞,尽知其名
CRITICAL

CVE-2026-107908 FalkorDB BoltReadHandler 堆越界写入漏洞

影响远程未授权攻击者可致拒绝服务并可能执行任意代码

AI 研判

FalkorDB 的 BoltReadHandler 函数(src/bolt/bolt_api.c)存在堆越界写入漏洞。攻击者向 Bolt 端口发送带有恶意 chunk size 的 Bolt RESET 消息即可触发。该漏洞影响 4.20.0 之前的版本,CVSS 评分 9.8。

影响范围

FalkorDB

FalkorDB 4.20.0 之前的版本;仅启用了 Bolt 端点(BOLT_PORT,默认关闭)的部署受影响。

漏洞详情

漏洞类型为堆越界写入。成因是处理函数仅用 ASSERT() 校验报文中的 16 位 chunk size,而 ASSERT 在 release 构建中被编译移除,导致攻击者可控制目标指针并向后移动最多约 64 KiB 的缓冲数据,越过读缓冲区起始位置。攻击者通过向 Bolt 端口发送特制 RESET 消息即可利用。

利用条件与风险

利用前提是目标启用了 Bolt 端点且攻击者可访问该端口,无需认证。成功利用可造成拒绝服务,并可能进一步实现任意代码执行,风险极高。

修复建议

建议升级至 FalkorDB 4.20.0 或更高版本。临时缓解措施为在不需要时禁用 Bolt 端点(BOLT_PORT),并限制该端口的网络访问。

原始情报

A heap-based out-of-bounds write in the BoltReadHandler function (src/bolt/bolt_api.c) in FalkorDB before 4.20.0 allows a remote unauthenticated attacker to cause a denial of service and possibly execute arbitrary code by sending a Bolt RESET message with an attacker-chosen chunk size to the Bolt port. The handler checks the size only with ASSERT(), which is compiled out in release builds, then computes a destination pointer from the wire-supplied 16-bit size and moves buffered data up to about 64 KiB backwards past the start of the read buffer. Only deployments that enable the Bolt endpoint (BOLT_PORT, disabled by default) are affected.