GHSA-h3m7-rqc4-7h9p

    Dashboard / Vulnerabilities / GHSA-h3m7-rqc4-7h9p

    GHSA-h3m7-rqc4-7h9p

    Published: 1 Mar 2024Last Modified: 10 Sept 2026

    Summary: Integer overflow in chunking helper causes dispatching to miss elements or panic

    Details: Any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type is affected by this problem. The issue may also lead to a panic rendering the server unavailable The following API methods are affected: - [CheckPermission](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.PermissionsService.CheckPermission) - [BulkCheckPermission](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.ExperimentalService.BulkCheckPermission) - [LookupSubjects](https://buf.build/authzed/api/docs/main:authzed.api.v1#authzed.api.v1.PermissionsService.LookupSubjects) #### Impact Permission checks that are expected to be allowed are instead denied, and lookup subjects will return fewer subjects than expected. #### Workarounds There is no workaround other than making sure that the SpiceDB cluster does not have very wide relations, with the maximum value being the maximum value of an 16-bit unsigned integer #### Remediations - AuthZed Dedicated customers: No action. AuthZed has upgraded all deployments. - AuthZed Serverless customers: No Action. AuthZed has upgraded all deployments. - AuthZed Enterprise customers: Upgrade to [v1.29.2-hotfix-enterprise.v1.hotfix.v1](https://github.com/authzed-enterprise/src/pkgs/container/spicedb-enterprise/182719614?tag=v1.29.2-hotfix-enterprise.v1.hotfix.v1) - Open Source users: Upgrade to v1.29.2

    Affected packages

    Package

    Name: github.com/authzed/spicedb

    Purl: pkg:golang/github.com/authzed/spicedb

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.29.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-h3m7-rqc4-7h9p | CVE-DB