Project

General

Profile

Actions

Security #6892

closed
PA PA

http2: oom on copying compressed headers

Security #6892: http2: oom on copying compressed headers

Added by Philippe Antoine about 2 years ago. Updated almost 2 years ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

390f09692eb99809c679d3f350c7cc185d163e1a

Severity:
CRITICAL
Disclosure Date:
06/20/2024

Description

Found by oss-fuzz:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67562

I would rate this critical : can allocate up to 4Gbytes of memory with 128 kbytes of traffic...

We have one bound of 65k for the maximum "dynamic headers table" size, but this can get multiplied by an arbitrary number of bytes representing one compressed header.

Not sure to backport it for 6 as HTTP2 is experimental there


Subtasks 2 (0 open2 closed)

Security #6893: http2: oom on copying compressed headers (7.0.x backport)ClosedPhilippe AntoineActions
Security #6972: http2: oom on copying compressed headers (6.0.x backport)ClosedPhilippe AntoineActions

Related issues 1 (0 open1 closed)

Related to Suricata - Security #6900: http2: timeout logging headersClosedPhilippe AntoineActions

OT Updated by OISF Ticketbot about 2 years ago Actions #1

  • Subtask #6893 added

OT Updated by OISF Ticketbot about 2 years ago Actions #2

  • Label deleted (Needs backport to 7.0)

PA Updated by Philippe Antoine about 2 years ago Actions #3

  • Private changed from No to Yes
  • Label Needs backport to 7.0 added

OT Updated by OISF Ticketbot about 2 years ago Actions #4

  • Label deleted (Needs backport to 7.0)

VJ Updated by Victor Julien about 2 years ago Actions #5

  • Severity changed from MODERATE to CRITICAL

PA Updated by Philippe Antoine about 2 years ago Actions #6

  • Status changed from New to In Review

Gitlab MR

PA Updated by Philippe Antoine about 2 years ago Actions #7

VJ Updated by Victor Julien almost 2 years ago Actions #8

  • Label Needs backport to 6.0 added

OT Updated by OISF Ticketbot almost 2 years ago Actions #9

  • Subtask #6972 added

OT Updated by OISF Ticketbot almost 2 years ago Actions #10

  • Label deleted (Needs backport to 6.0)

SB Updated by Shivani Bhardwaj almost 2 years ago Actions #11

  • CVE set to 2024-32663

VJ Updated by Victor Julien almost 2 years ago Actions #12

  • Status changed from In Review to Closed
  • Git IDs updated (diff)
Actions

Also available in: PDF Atom