Summary
The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.
Impact
Severity: Low
If affected, this can result in unbounded memory growth and unnecessary CPU consumption, or denial of service.
To determine if vulnerable, all these things must be true:
- You are using HTTP/2, either as a server or a client.
- Your application does not fully drain incoming request or response bodies (for example, a proxy applying backpressure, or a client that delays reading the body).
- The direct remote peer is malicious and intentionally sends large numbers of empty
DATA frames.
Patches
We have released the following patch version(s):
Workarounds
Besides upgrading, you can take the following actions:
- Actively drain all incoming body streams.
- Place a proxy in-between your
h2 service and a peer that enforces empty DATA frame limits.
Credits
- Reported-by: SCADA StrangeLove
- Patched-by: Sean McArthur
Summary
The
h2crate, used internally byhyper, had a flaw that would accept and queue emptyDATAframes without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.Impact
Severity: Low
If affected, this can result in unbounded memory growth and unnecessary CPU consumption, or denial of service.
To determine if vulnerable, all these things must be true:
DATAframes.Patches
We have released the following patch version(s):
Workarounds
Besides upgrading, you can take the following actions:
h2service and a peer that enforces empty DATA frame limits.Credits