scd: Have a limit for data object handling
Closed, ResolvedPublic

Assigned To
Authored By
• gniibe
Jun 1 2026, 3:24 AM

Description

In scdaemon, there exists a possible DoS attack vector: a malicious/buggy device tries to return large DO by SW_MORE_DATA .

Reported by: Jakub Jelen, Found by AISLE in partnership with Red Hat

Event Timeline

• gniibe triaged this task as Normal priority.Jun 1 2026, 3:24 AM
• gniibe created this task.
• gniibe mentioned this in Unknown Object (Maniphest Task).
• gniibe changed the task status from Open to Testing.Jun 2 2026, 3:56 AM
• gniibe shifted this object from the Restricted Space space to the S1 Public space.Jun 8 2026, 3:21 AM
• gniibe changed the visibility from "g10code (Project)" to "All Users".
• gniibe changed the edit policy from "Custom Policy" to "All Users".
• gniibe changed the visibility from "All Users" to "Public (No Login Required)".
• gniibe mentioned this in Unknown Object (Maniphest Task).Jun 8 2026, 3:32 AM