Bloomberg Comdb2 Distributed Transaction Heartbeat Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the Bloomberg Comdb2 database version 8.1. The issue arises when the database handles distributed transaction heartbeats. An attacker can connect to a database instance over TCP and send a specially crafted protocol buffer message, leading to a denial-of-service condition by causing the database process to crash.

Impact

Exploiting this vulnerability causes the Comdb2 database process to terminate unexpectedly, leading to a denial-of-service condition where the database becomes unavailable.

Reproduction

The vulnerability can be reproduced by sending two 'HEARTBEAT' protocol buffer messages with the same transaction ID to a Comdb2 database instance. This can be done by connecting to the database over TCP and using the 'newsql' application socket to send the crafted messages. The first message will be processed normally, but the second will trigger an 'abort' command, causing the database process to crash.

Remediation

Users can upgrade to the latest version of Bloomberg Comdb2 to address this vulnerability.

Added: Jul 22, 2025, 4:35 PM
Updated: Jul 22, 2025, 4:35 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
0.3
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.