CVE-2024-21634: Ion Java StackOverflow vulnerability

Published Jan 3, 2024
·
Updated

Impact

A potential denial-of-service issue exists in ion-java for applications that use ion-java to:

Deserialize Ion text encoded data, or Deserialize Ion text or binary encoded data into the IonValue model and then invoke certain IonValue methods on that in-memory representation.

An actor could craft Ion data that, when loaded by the affected application and/or processed using the IonValue model, results in a StackOverflowError originating from the ion-java library.

Impacted versions: <1.10.5

Patches

The patch is included in ion-java >= 1.10.5.

Workarounds

Do not load data which originated from an untrusted source or that could have been tampered with. Only load data you trust.

----

If you have any questions or comments about this advisory, we ask that you contact AWS/Amazon Security via our vulnerability reporting page [1] or directly via email to aws-security@amazon.com. Please do not create a public GitHub issue.

[1] https://aws.amazon.com/security/vulnerability-reporting

Other sources

Amazon Ion is a Java implementation of the Ion data notation. Prior to version 1.10.5, a potential denial-of-service issue exists in ion-java for applications that use ion-java to deserialize Ion text encoded data, or deserialize Ion text or binary encoded data into the IonValue model and then invoke certain IonValue methods on that in-memory representation. An actor could craft Ion data that, when loaded by the affected application and/or processed using the IonValue model, results in a StackOverflowError originating from the ion-java library. The patch is included in ion-java 1.10.5. As a workaround, do not load data which originated from an untrusted source or that could have been tampered with.

Red Hat

Amazon Ion is vulnerable to a denial of service, caused by a stack-based overflow in ion-java for applications. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.

IBM

Affected Software

4 affected componentsFixes available
maven/software.amazon.ion:ion-java<1.10.5
maven/com.amazon.ion:ion-java<1.10.5
1.10.5
IBM Cognos Controller<=11.0.0 - 11.0.1
Amazon Ion<1.10.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/com.amazon.ion:ion-java to a version that resolves this vulnerability.

    Fixed in 1.10.5
  2. Upgrade

    Upgrade ion-java to a version that resolves this vulnerability.

    Fixed in 1.10.5
  3. Compensating control

    Do not load Ion data that originated from an untrusted source or that could have been tampered with.

  4. Compensating control

    As a workaround, deserialize Ion text (encoded) data only from trusted sources, or deserialize Ion text or binary encoded data into the IonValue model and invoke the affected IonValue methods only on that in-memory representation derived from trusted data.

Event History

Jan 3, 2024
Advisory Published
via GitHub·10:04 PM
CVE Published
via MITRE·10:46 PM
Data Sourced
via MITRE·10:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Aug 13, 2024
Data Sourced
via Red Hat·12:49 PM
DescriptionSeverityAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-21634?

CVE-2024-21634 is categorized as a potential denial-of-service vulnerability.

2

How do I fix CVE-2024-21634?

To mitigate CVE-2024-21634, update to ion-java version 1.10.5 or later.

3

Which software is affected by CVE-2024-21634?

CVE-2024-21634 affects Amazon Ion and its Java library ion-java versions prior to 1.10.5.

4

Can CVE-2024-21634 impact applications using IBM Cognos Controller?

Yes, CVE-2024-21634 can impact IBM Cognos Controller versions 11.0.0 to 11.0.1 if they utilize ion-java.

5

What methods in IonValue are associated with CVE-2024-21634?

CVE-2024-21634 arises when certain IonValue methods are invoked after deserializing Ion text or binary data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203