Bug 2417164 (CVE-2025-65942) - CVE-2025-65942 VictoriaMetrics: VictoriaMetrics Snappy Decoder DoS Vulnerability is Causing OOM
Summary: CVE-2025-65942 VictoriaMetrics: VictoriaMetrics Snappy Decoder DoS Vulnerabil...
Keywords:
Status: NEW
Alias: CVE-2025-65942
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2431550 2431551 2431552 2431553
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-11-25 23:01 UTC by OSIDB Bzimport
Modified: 2026-01-21 10:34 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-11-25 23:01:32 UTC
VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.110.23, from 1.111.0 to before 1.122.8, and from 1.123.0 to before 1.129.1, affected versions are vulnerable to DoS attacks because the snappy decoder ignored VictoriaMetrics request size limits allowing malformed blocks to trigger excessive memory use. This could lead to OOM errors and service instability. The fix enforces block-size checks based on MaxRequest limits. This issue has been patched in versions 1.110.23, 1.122.8, and 1.129.1.


Note You need to log in before you can comment on or make changes to this bug.