CVE-2024-52805

Publication date 3 December 2024

Last updated 8 April 2025


Ubuntu priority

Synapse is an open-source Matrix homeserver. In Synapse before 1.120.1, multipart/form-data requests can in certain configurations transiently increase memory consumption beyond expected levels while processing the request, which can be used to amplify denial of service attacks. Synapse 1.120.1 resolves the issue by denying requests with unsupported multipart/form-data content type.

Read the notes from the security team

Status

Package Ubuntu Release Status
matrix-synapse 24.10 oracular
Vulnerable, fix deferred
24.04 LTS noble
Vulnerable, fix deferred
22.04 LTS jammy
Vulnerable, fix deferred
20.04 LTS focal
Vulnerable, fix deferred
18.04 LTS bionic
Vulnerable, fix deferred

Notes


john-breton

As of 7/4/2025 no patch for this CVE exists. It may be possible to extract the fix from 1.120.1 source, but such an undertaking would require significant effort.