Project

General

Profile

Actions

Security #7658

closed

http2: global tx (stream id 0) may open file and never close it

Added by Philippe Antoine 4 months ago. Updated 11 days ago.

Status:
Closed
Priority:
Normal
Target version:
Affected Versions:
Label:
Git IDs:

1d6d331752e933c46aca0ae7a9679b27462246e3

Severity:
HIGH
Disclosure Date:
07/26/2025

Description

Per RFC 9113 section 5.1.1

the stream identifier of zero cannot be used to establish a new stream

So, we should not accept DATA frame with a stream id 0

Somes from oss-fuzz https://issues.oss-fuzz.com/u/1/issues/42534790


Subtasks 1 (0 open1 closed)

Security #7659: http2: global tx (stream id 0) may open file and never close it (7.0.x backport)ClosedPhilippe AntoineActions
Actions

Also available in: Atom PDF