CWE•Base•Incomplete•4 recent CVEs
CWE-1322Use of Blocking Code in Single-threaded, Non-blocking Context
Description
The product uses a non-blocking model that relies on a single threaded process for features such as scalability, but it contains code that can block when it is invoked.
[object Object]
Common consequences
- Availability→DoS: Resource Consumption (CPU)An unexpected call to blocking code can trigger an infinite loop, or a large loop that causes the software to pause and wait indefinitely.
Potential mitigations
- ImplementationGenerally speaking, blocking calls should be replaced with non-blocking alternatives that can be used asynchronously. Expensive computations should be passed off to worker threads, although the correct approach depends on the framework being used.
- ImplementationFor expensive computations, consider breaking them up into multiple smaller computations. Refer to the documentation of the framework being used for guidance.