CVE-2026-94029 Apache MINA SSHD SFTP 服务端内存耗尽漏洞
影响攻击者可耗尽服务端内存导致服务不可用
Apache MINA SSHD 的 sshd-sftp 组件在实现 SFTP v6 的 check-file-name/check-file-handle 扩展时存在缺陷。服务端会将生成的哈希回复消息完整累积在内存中,未对回复大小设限。攻击者通过使用极小 block size 对超大(可为稀疏)文件发起请求,可产生海量哈希,从而耗尽服务端内存并导致服务宕机。
影响范围
Apache MINA SSHD 1.0.0 至 2.19.0,以及 3.0.0-M1 至 3.0.0-M5 版本受影响。
漏洞详情
漏洞类型为服务端内存耗尽(资源管理不当)。成因是 SFTP v6 的 check-file-name/check-file-handle 扩展在计算文件哈希时,按 文件大小/block size 生成哈希数量,且将整个回复消息在服务端内存中累积,未限制回复大小。攻击者只需以最小 block size(如 256)对超大或稀疏文件发起请求,即可生成极多哈希,使回复消息体积膨胀,最终耗尽服务端内存。
利用条件与风险
利用前提是目标开放 SFTP 服务且启用了相关扩展,攻击者需具备可发起 SFTP 请求的访问权限。实战中可造成服务端内存耗尽、服务不可用,属于拒绝服务风险,CVSS 6.5 为中危。
修复建议
官方建议升级至 2.20.0 或 3.0.0-M6 版本,该版本通过对回复消息大小施加最大限制修复此问题。临时缓解措施可参考 OpenSSH 等实现,对 SFTP 消息大小设置通用上限(通常约 256kB),暂无其他公开信息。
Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 2.19.0 and 3.0.0-M1 to 3.0.0-M5, component sshd-sftp, in the SFTP v6 check-file-name/check-file-handle extension. Apache MINA SSHD is a Java library for client-side and server-side SSH.
Using a very small “block size” (for instance 256, which is the minimum) on a huge file generates many (file size / block size) hashes. The resulting SFTP reply message was accumulated fully in memory server-side, which could, with a suitably large (possibly sparse) file exhaust the server-side memory, taking down the server.
Users are recommended to upgrade to version 2.20.0 or 3.0.0-M6, which fix this issue by imposing a maximum limit on the size of the reply. Many SFTP implementations have a general limit on the size of SFTP messages anyway; typically 256kB as in OpenSSH or also in Apache MINA SSHD.