XMLWordPrintable

Details

    • Bug
    • Resolution: Done
    • Undefined
    • 1.3.3
    • 1.3.1
    • Security, Service Binding
    • None
    • False
    • None
    • False
    • Hide
      Before this update an attacker could cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache was capped, an attacker sending very large keys could cause the server to allocate approximately 64 MiB per open connection.
      Show
      Before this update an attacker could cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache was capped, an attacker sending very large keys could cause the server to allocate approximately 64 MiB per open connection.
    • CVE - Common Vulnerabilities and Exposures
    • AppSvc Sprint 228

    Description

      Description of problem:

      https://nvd.nist.gov/vuln/detail/CVE-2022-41717

      Identified by:

      Prerequisites (if any, like setup, operators/versions):

      Steps to Reproduce

      1. <steps>

      Actual results:

      Expected results:

      Reproducibility (Always/Intermittent/Only Once):

      Build Details:

      Additional info:

      Documentation Requirement: Yes/No (needs-docs|upstream-docs / no-doc)

      Upstream: <Inputs/Requirement details>/ Not Applicable

      Downstream: <Type: Doc defect/More inputs to doc>/ Not Applicable

      Provide link to the relevant section
      Provide doc inputs and details required

      Release Notes Type: <New Feature/Enhancement/Known Issue/Bug
      fix/Breaking change/Deprecated Functionality/Technology Preview>

      Attachments

        Activity

          People

            pmacik@redhat.com Pavel Macik
            pmacik@redhat.com Pavel Macik
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: