CVE-2024-27101
NixOS vulnerability analysis and mitigation

Overview

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. An integer overflow vulnerability (CVE-2024-27101) was discovered in the chunking helper that causes dispatching to miss elements or panic. The vulnerability affects any SpiceDB cluster with any schema where a resource being checked has more than 65535 relationships for the same resource and subject type. This vulnerability was disclosed on March 1, 2024, and has been fixed in version 1.29.2 (GitHub Advisory).

Technical details

The vulnerability is caused by an integer overflow in the chunking helper functionality. The issue affects the CheckPermission, BulkCheckPermission, and LookupSubjects API methods. The vulnerability has been assigned a CVSS v3.1 base score of 7.3 (High) with the vector string CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:H, indicating network attack vector, high attack complexity, high privileges required, user interaction required, changed scope, and high impact on integrity and availability (GitHub Advisory).

Impact

The vulnerability can cause permission checks that are expected to be allowed to be denied instead, and lookup subjects will return fewer subjects than expected. Additionally, the issue may lead to a panic rendering the server unavailable (GitHub Advisory).

Exploitability

The vulnerability requires high attack complexity and high privileges to exploit. User interaction is required, and the attack vector is network-based (GitHub Advisory).

Mitigation and workarounds

There is no workaround other than ensuring that the SpiceDB cluster does not have very wide relations, with the maximum value being the maximum value of a 16-bit unsigned integer. AuthZed Dedicated and Serverless customers require no action as AuthZed has upgraded all deployments. AuthZed Enterprise customers should upgrade to v1.29.2-hotfix-enterprise.v1.hotfix.v1, while Open Source users should upgrade to v1.29.2 (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • headlamp-fips
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • argo-workflows-3.7
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management