Описание
Security update for terraform-provider-null
This update for terraform-provider-null fixes the following issues:
- CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278269).
- CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278272).
- gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1278267).
Список пакетов
SUSE Linux Enterprise Module for Public Cloud 15 SP4
SUSE Linux Enterprise Module for Public Cloud 15 SP5
Ссылки
- Link for SUSE-SU-2026:4062-1
- E-Mail link for SUSE-SU-2026:4062-1
- SUSE Security Ratings
- SUSE Bug 1278267
- SUSE Bug 1278269
- SUSE Bug 1278272
- SUSE CVE CVE-2026-84303 page
- SUSE CVE CVE-2026-84304 page
Описание
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.
Затронутые продукты
Ссылки
- CVE-2026-84303
- SUSE Bug 1278268
Описание
gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.
Затронутые продукты
Ссылки
- CVE-2026-84304
- SUSE Bug 1278271