
JBoss क्लाइंट में UserTransaction का बार-बार उपयोग करने पर मेमोरी लीक को प्रदर्शित करता है, साथ ही CVE-2022-0853 के लिए PoC और विश्लेषण शामिल है।
jboss क्लाइंट पक्ष पर एक मेमोरी लीक, जब UserTransaction का बार-बार उपयोग किया जाता है।
जैसे:
private void testTransaction() throws Exception {
for(int i=1; i< 500000; i++) {
System.out.println("Starting process " + i);
// get the UserTransaction and EJB Proxy
Context ctx = getInitialContext(host, port, username, password);
UserTransaction tx = getUserTransaction(ctx);
ControllerRemote cr = (ControllerRemote)
ctx.lookup("Controller/Controller" + "!com.test.usertransaction.ControllerRemote");
try {
tx.begin();
}
catch(Exception ex1) {
ex1.printStackTrace();
}
//System.out.println("user transaction started");
cr.mainCall();
try {
tx.commit();;
}
catch(Exception ex1) {
ex1.printStackTrace();
throw ex1;
}
//System.out.println("commited user transaction");
if(ctx != null)
ctx.close();
}
}
लेन-देन एक दूरस्थ क्लाइंट द्वारा EAP 7.3 में तैनात EJB पर निष्पादित किया जाता है। लेन-देन 50000 बार दोहराया जाता है। पुनरावृत्तियों के अंत में मेमोरी लीक देखा जाता है। 32% मेमोरी org.wildfly.transaction.client.provider.remoting.TransactionClientChannel द्वारा घेर ली जाती है।