Intel

AIKIDO-2024-10462

minio is vulnerable to Deadlock

Deadlock Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Nov 20, 2024

21

Low Risk

This Affects:

pythonminio
2.2.5 - 7.2.10
Fixed in 7.2.11
Are you affected? Scan for Free

TL;DR

Affected versions of this package are prone to deadlocks during large file uploads due to a data race in the Worker.run() function. This issue arises in specific scenarios and can cause the system to hang, disrupting the upload process and, depending on your system setup, cause Denial of Service (DoS).

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges

Background info

minio is vulnerable to Deadlock in versions 2.2.5 - 7.2.10.

How to fix this

Upgrade the minio library to the patch version.