Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:4062-1

Опубликовано: 08 сент. 2026
Источник: suse-cvrf

Описание

Security update for terraform-provider-null

This update for terraform-provider-null fixes the following issues:

  • CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278269).
  • CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278272).
  • gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1278267).

Список пакетов

SUSE Linux Enterprise Module for Public Cloud 15 SP4
terraform-provider-null-3.0.0-150200.6.27.1
SUSE Linux Enterprise Module for Public Cloud 15 SP5
terraform-provider-null-3.0.0-150200.6.27.1

Описание

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, the xDS RBAC HTTP filter in internal/xds/httpfilter/rbac/rbac.go does not lowercase header matcher names in normalizeHeaderMatcher even though incoming metadata keys are lowercase. A DENY policy using a mixed-case name such as X-Role or User-Agent therefore does not match and fails open, allowing requests that should be rejected. The same case mismatch permits :Scheme or Grpc-Status to evade gRFC A41 validation and prevents Host from being rewritten to :authority. This issue is fixed in version 1.83.1.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 15 SP4:terraform-provider-null-3.0.0-150200.6.27.1
SUSE Linux Enterprise Module for Public Cloud 15 SP5:terraform-provider-null-3.0.0-150200.6.27.1

Ссылки

Описание

gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, internal/transport/transport.go stores each fragmented HTTP/2 DATA frame as a separate recvMsg in recvBuffer, so millions of one-byte frames can consume disproportionate heap memory even when payload bytes remain within connection and stream flow-control windows. An unauthenticated remote attacker can use concurrent multiplexed streams to exhaust process memory and cause a runtime panic or out-of-memory termination. Receive-buffer compaction is enabled by default and can be controlled temporarily with GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION. This issue is fixed in version 1.83.1.


Затронутые продукты
SUSE Linux Enterprise Module for Public Cloud 15 SP4:terraform-provider-null-3.0.0-150200.6.27.1
SUSE Linux Enterprise Module for Public Cloud 15 SP5:terraform-provider-null-3.0.0-150200.6.27.1

Ссылки
Уязвимость SUSE-SU-2026:4062-1