Количество 19
Количество 19
CVE-2026-35469
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
CVE-2026-35469
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
CVE-2026-35469
spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1.
CVE-2026-35469
SpdyStream: DOS on CRI
CVE-2026-35469
spdystream is a Go library for multiplexing streams over SPDY connecti ...
GHSA-pc3f-x583-g7j2
SpdyStream: DOS on CRI
SUSE-SU-2026:2460-1
Security update for kubernetes-old
SUSE-SU-2026:2345-1
Security update for kubernetes1.25
SUSE-SU-2026:2344-1
Security update for kubernetes1.28
SUSE-SU-2026:2343-1
Security update for kubernetes1.24
SUSE-SU-2026:2342-1
Security update for kubernetes
SUSE-SU-2026:2340-1
Security update for kubernetes1.23
SUSE-SU-2026:2339-1
Security update for kubernetes1.27
SUSE-SU-2026:2325-1
Security update for kubernetes1.26
SUSE-SU-2026:2322-1
Security update for kubernetes1.24
SUSE-SU-2026:2315-1
Security update for kubernetes1.23
SUSE-SU-2026:2804-1
Security update for kubevirt
SUSE-SU-2026:2783-1
Security update for kubevirt-1.6
openSUSE-SU-2026:21213-1
Security update for containerd
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-35469 spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-35469 spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-35469 spdystream is a Go library for multiplexing streams over SPDY connections. In versions 0.5.0 and below, the SPDY/3 frame parser does not validate attacker-controlled counts and lengths before allocating memory. Three allocation paths are affected: the SETTINGS frame entry count, the header count in parseHeaderValueBlock, and individual header field sizes — all read as 32-bit integers and used directly as allocation sizes with no bounds checking. Because SPDY header blocks are zlib-compressed, a small on-the-wire payload can decompress into large attacker-controlled values. A remote peer that can send SPDY frames to a service using spdystream can exhaust process memory and cause an out-of-memory crash with a single crafted control frame. This issue has been fixed in version 0.5.1. | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
CVE-2026-35469 SpdyStream: DOS on CRI | CVSS3: 8.1 | 1% Низкий | 4 месяца назад | |
CVE-2026-35469 spdystream is a Go library for multiplexing streams over SPDY connecti ... | CVSS3: 6.5 | 1% Низкий | 4 месяца назад | |
GHSA-pc3f-x583-g7j2 SpdyStream: DOS on CRI | 1% Низкий | 4 месяца назад | ||
SUSE-SU-2026:2460-1 Security update for kubernetes-old | около 2 месяцев назад | |||
SUSE-SU-2026:2345-1 Security update for kubernetes1.25 | около 2 месяцев назад | |||
SUSE-SU-2026:2344-1 Security update for kubernetes1.28 | около 2 месяцев назад | |||
SUSE-SU-2026:2343-1 Security update for kubernetes1.24 | около 2 месяцев назад | |||
SUSE-SU-2026:2342-1 Security update for kubernetes | около 2 месяцев назад | |||
SUSE-SU-2026:2340-1 Security update for kubernetes1.23 | около 2 месяцев назад | |||
SUSE-SU-2026:2339-1 Security update for kubernetes1.27 | около 2 месяцев назад | |||
SUSE-SU-2026:2325-1 Security update for kubernetes1.26 | около 2 месяцев назад | |||
SUSE-SU-2026:2322-1 Security update for kubernetes1.24 | около 2 месяцев назад | |||
SUSE-SU-2026:2315-1 Security update for kubernetes1.23 | около 2 месяцев назад | |||
SUSE-SU-2026:2804-1 Security update for kubevirt | 29 дней назад | |||
SUSE-SU-2026:2783-1 Security update for kubevirt-1.6 | около 1 месяца назад | |||
openSUSE-SU-2026:21213-1 Security update for containerd | около 1 месяца назад |
Уязвимостей на страницу