Описание
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| golang-1.17 | fixed | 1.17.5-1 | package | |
| golang-1.15 | fixed | 1.15.15-5 | package | |
| golang-1.15 | fixed | 1.15.15-1~deb11u2 | bullseye | package |
| golang-1.11 | removed | package | ||
| golang-1.8 | removed | package | ||
| golang-1.7 | removed | package | ||
| golang-golang-x-net | fixed | 1:0.0+git20211209.491a49a+dfsg-1 | package | |
| golang-golang-x-net | no-dsa | bullseye | package | |
| golang-golang-x-net-dev | removed | package | ||
| golang-golang-x-net-dev | postponed | buster | package | |
| golang-golang-x-net-dev | postponed | stretch | package |
Примечания
https://github.com/golang/go/issues/50058
https://groups.google.com/g/golang-announce/c/hcmEScgc00k/m/ZWnOjeY4CQAJ
https://github.com/golang/go/commit/48d948963c5ce7add72af5665a871caff6c1d35a (go1.17.5)
https://github.com/golang/go/commit/d0aebe3e74fe14799f97ddd3f01129697c6a290a (go1.16.12)
https://github.com/golang/net/commit/491a49abca63de5e07ef554052d180a1b5fe2d70
Связанные уязвимости
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.