CVE-2026-102509 Apache PLC4X PLC4J 拒绝服务漏洞
影响攻击者可耗尽客户端内存或栈,导致拒绝服务
Apache PLC4X 的 Java 实现(PLC4J)存在内存分配过大、资源无限制分配及不受控递归等缺陷。恶意或伪造的设备可借此耗尽客户端应用的内存或栈,造成拒绝服务。在 OPC UA 驱动中,这些缺陷可在认证前被触发。
影响范围
影响 Apache PLC4X PLC4J 0.10.0 至 0.13.1 版本,涉及长度前缀字节串分配、生成式协议解析器数组预分配以及 OPC UA 驱动消息分块累积等问题。
漏洞详情
漏洞类型为资源耗尽型拒绝服务。成因包括:按报文声明的长度预先分配字节串而未与实际接收数据核对;协议解析器按报文声明的元素数量预分配列表,单个计数字段即可触发数 GB 分配;OPC UA 驱动累积消息分块时未强制协商的最大值。攻击者可通过伪造设备发送特制报文触发上述路径。
利用条件与风险
OPC UA 驱动中的缺陷可在安全通道和会话建立阶段、服务器身份绑定之前被触发,因此即使配置了受信任服务器,能冒充该服务器的攻击者仍可利用,实战风险较高。
修复建议
建议升级至修复该漏洞的 Apache PLC4X 版本(具体版本暂无公开信息),并关注官方安全公告;临时缓解措施暂无公开信息。
Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits, and Uncontrolled Recursion in the Java implementation of Apache PLC4X (PLC4J) allow a malicious or impersonated device to exhaust the memory or stack of the client application, causing a denial of service.
In the OPC UA driver these defects are reachable before authentication: the offending data is parsed while the secure channel and session are being established, before the server’s identity has been bound to it. Configuring a trusted server therefore does not prevent exploitation by an attacker who can
impersonate it.
The individual defects are:
– Length-prefixed byte strings are allocated at the size claimed on the wire before the length is checked against the data actually received (0.10.0 through 0.13.1).
– Array fields in generated protocol parsers pre-allocate a list with the element count claimed on the wire, allowing a single count field to trigger a multi-gigabyte allocation. This parser is shared by all PLC4J drivers; the OPC UA driver is the verified pre-authentication path (0.10.0 through 0.13.1).
– The OPC UA driver accumulates message chunks without enforcing the negotiated maximum chunk count and message size (0.12.0 through 0.13.1).
– The OPC UA driver pre-allocates collections using element counts received from the server (0.10.0 through 0.13.1).
– Recursive protocol types are parsed without a nesting-depth limit. The same defect in the Go implementation is covered by CVE-2026-102510 https://cveprocess.apache.org/cve5/CVE-2026-102510 .
This issue affects Apache PLC4X: from 0.10.0 before 1.0.0.
Users are recommended to upgrade to version 1.0.0, which fixes the issue.