GHSA-fm35-jgg3-3grx

    Dashboard / Vulnerabilities / GHSA-fm35-jgg3-3grx

    GHSA-fm35-jgg3-3grx

    Published: 18 Mar 2022Last Modified: 8 Sept 2026

    Summary: NaN/INF in serverbound movement packets can crash clients and servers

    Details: ### Impact A malicious client may send a `MovePlayerPacket` to the server whose position or rotation contains NaN or INF. Since neither the server nor vanilla client handles this properly, a number of interesting side effects come into play. - The server may crash in various ways if this exploit is used, because some mathematical operations on NaN/INF generate PHP warnings, which are converted into exceptions. - Clients may not be able to see other clients who have a NaN/INF rotation. - Clients may also crash in such cases. ### Patches A patch for this was included in the 3.18.1 release: https://github.com/pmmp/PocketMine-MP/commit/fb20bb38327b4c08ee3976640cd0dd547388a638 ### Workarounds Workarounds could be implemented as plugins using `DataPacketReceiveEvent` to block any inbound movement packets containing bogus values. ### For more information If you have any questions or comments about this advisory: - Open an issue in [pmmp/PocketMine-MP](https://github.com/pmmp/PocketMine-MP) - Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: pocketmine/pocketmine-mp

    Purl: pkg:composer/pocketmine/pocketmine-mp

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.18.1

    Affected versions

    3.0.0
    3.0.1
    3.0.10
    3.0.11
    3.0.12
    3.0.2
    3.0.3
    3.0.4
    3.0.5
    3.0.6
    3.0.7
    3.0.8
    3.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-fm35-jgg3-3grx | CVE-DB