Asymmetric Resource Consumption (Amplification) Affecting neoraider/fastd package, versions [,23)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.04% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NEORAIDERFASTD-8664880
  • published29 Jan 2025
  • disclosed27 Jan 2025
  • creditUnknown

Introduced: 27 Jan 2025

NewCVE-2025-24356  (opens in a new tab)
CWE-405  (opens in a new tab)

How to fix?

Upgrade neoraider/fastd to version 23 or higher.

Overview

Affected versions of this package are vulnerable to Asymmetric Resource Consumption (Amplification) by abusing the fast reconnect feature, which is triggered by any received packet from an unknown address+port combination. An attacker can amplify UDP traffic to render the service unavailable by sending minimally-sized packets with a spoofed source address.

Note: Applications using the client role that configure their peers using the remote config option are unaffected because they do not respond to unknown requests with a handshake.

CVSS Scores

version 4.0
version 3.1