Project

General

Profile

Actions

Security #6481

closed
PA PA

http2: quadratic complexity in find_or_create_tx not bounded by max-tx

Security #6481: http2: quadratic complexity in find_or_create_tx not bounded by max-tx

Added by Philippe Antoine over 2 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

80abc22f6475b6a87a33166729a871203f34d578

Severity:
CRITICAL
Disclosure Date:
01/16/2024

Description

As a single parsing round can create more transactions than max-tx
Found by oss-fuzz:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=63345


Subtasks 2 (0 open2 closed)

Security #6531: http2: quadratic complexity in find_or_create_tx not bounded by max-tx (7.0.x backport)ClosedPhilippe AntoineActions
Security #6660: http2: quadratic complexity in find_or_create_tx not bounded by max-tx (6.0.x backport)ClosedPhilippe AntoineActions

PA Updated by Philippe Antoine over 2 years ago Actions #1

  • Status changed from New to In Review

Gitlab

VJ Updated by Victor Julien over 2 years ago Actions #2

  • Target version changed from 7.0.3 to 8.0.0-beta1
  • Label Needs backport to 7.0 added

OT Updated by OISF Ticketbot over 2 years ago Actions #3

  • Subtask #6531 added

OT Updated by OISF Ticketbot over 2 years ago Actions #4

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine over 2 years ago Actions #5

  • Disclosure Date set to 01/16/2024

VJ Updated by Victor Julien over 2 years ago Actions #6

  • Severity changed from MODERATE to CRITICAL

Issue is about number of transactions created from a single block of data. Since the minimal size to create a tx is small, it can still be a very large number.

VJ Updated by Victor Julien over 2 years ago Actions #7

  • Label Needs backport to 6.0 added

OT Updated by OISF Ticketbot over 2 years ago Actions #8

  • Subtask #6660 added

OT Updated by OISF Ticketbot over 2 years ago Actions #9

  • Label deleted (Needs backport to 6.0)

VJ Updated by Victor Julien about 2 years ago Actions #10

  • Status changed from In Review to Resolved
  • CVE set to 2024-23836

PA Updated by Philippe Antoine about 2 years ago Actions #11

  • Status changed from Resolved to Closed
  • Git IDs updated (diff)

VJ Updated by Victor Julien about 2 years ago Actions #12

  • Private changed from Yes to No
Actions

Also available in: PDF Atom