Resource Exhaustion Affecting cmark-gfm package, versions <0.29.0.gfm.3-3ubuntu0.1~esm1


Severity

Recommended
medium

Based on Ubuntu security rating.

Threat Intelligence

EPSS
1.03% (60th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU2204-CMARKGFM-5402081
  • published26 Feb 2025
  • disclosed31 Mar 2023

Introduced: 31 Mar 2023

CVE-2023-26485  (opens in a new tab)
CWE-400  (opens in a new tab)
CWE-407  (opens in a new tab)

How to fix?

Upgrade Ubuntu:22.04 cmark-gfm to version 0.29.0.gfm.3-3ubuntu0.1~esm1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cmark-gfm package and not the cmark-gfm package as distributed by Ubuntu. See How to fix? for Ubuntu:22.04 relevant fixed versions and status.

cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service. This CVE covers quadratic complexity issues when parsing text which leads with either large numbers of _ characters. This issue has been addressed in version 0.29.0.gfm.10. Users are advised to upgrade. Users unable to upgrade should validate that their input comes from trusted sources.

Impact

A polynomial time complexity issue in cmark-gfm may lead to unbounded resource exhaustion and subsequent denial of service.

Proof of concept

$ ~/cmark-gfm$ python3 -c &#39;pad = &#34;_&#34; * 100000; print(pad + &#34;.&#34; + pad, end=&#34;&#34;)&#39; | time ./build/src/cmark-gfm --to plaintext

Increasing the number 10000 in the above commands causes the running time to increase quadratically.

Patches

This vulnerability have been patched in 0.29.0.gfm.10.

Note on cmark and cmark-gfm

XXX: TBD

cmark-gfm is a fork of cmark that adds the GitHub Flavored Markdown extensions. The two codebases have diverged over time, but share a common core. These bugs affect both cmark and cmark-gfm.

Credit

We would like to thank @gravypod for reporting this vulnerability.

References

https://en.wikipedia.org/wiki/Time_complexity

For more information

If you have any questions or comments about this advisory:

CVSS Base Scores

version 3.1