漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
nebula-mesh: Decrypted CA private key persists in heap after signing
Vulnerability Description
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 constructs a CAManager with the plaintext ed25519.PrivateKey after unwrapping via the master key; internal/pki/ca.go:13-16 stores it. Callers at internal/api/enroll.go:116, internal/api/updates.go:297, and internal/api/mobile_bundle.go:40 use the manager for one Sign() and drop the reference on function return — but the underlying slice contents are not wiped before release. The keystore package's contract (internal/keystore/keystore.go doc: "Callers MUST zeroise the returned plaintext DEK as soon as it is no longer needed") is not met by the CAManager consumer. Decrypted CA private keys persist in process heap until Go's GC scavenges the underlying slice — minutes to hours under load, indefinitely on idle servers. This issue has been patched in version 0.3.7.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
在释放前清理堆内存不恰当(堆检查)
Vulnerability Title
Forgekeep nebula-mesh 资源管理错误漏洞
Vulnerability Description
Forgekeep nebula-mesh是Forgekeep团队的一系列网络代理和VPN整合软件。 Forgekeep nebula-mesh 0.3.7之前版本存在资源管理错误漏洞,该漏洞源于未正确擦除解密后的CA私钥,导致私钥在进程堆中持久存在。
CVSS Information
N/A
Vulnerability Type
N/A