Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q6cp-qfwq-4gcv

Опубликовано: 05 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

h2 servers vulnerable to degradation of service with CONTINUATION Flood

An attacker can send a flood of CONTINUATION frames, causing h2 to process them indefinitely. This results in an increase in CPU usage.

Tokio task budget helps prevent this from a complete denial-of-service, as the server can still respond to legitimate requests, albeit with increased latency.

More details at https://seanmonstar.com/blog/hyper-http2-continuation-flood/.

Patches available for 0.4.x and 0.3.x versions.

Пакеты

Наименование

h2

rust
Затронутые версииВерсия исправления

< 0.3.26

0.3.26

Наименование

h2

rust
Затронутые версииВерсия исправления

>= 0.4.0, < 0.4.4

0.4.4

5.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770

5.3 Medium

CVSS3

Дефекты

CWE-400
CWE-770