Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

RUSTSEC-2024-0332: Degradation of service in h2 servers with CONTINUATION Flood #6

Open
github-actions bot opened this issue Nov 1, 2024 · 0 comments

Comments

@github-actions
Copy link

github-actions bot commented Nov 1, 2024

Degradation of service in h2 servers with CONTINUATION Flood

Details
Package h2
Version 0.2.7
Date 2024-04-03
Patched versions ^0.3.26,>=0.4.4

An attacker can send a flood of CONTINUATION frames, causing h2 to process them indefinitely.
This results in an increase in CPU usage.

Tokio task budget helps prevent this from a complete denial-of-service, as the server can still
respond to legitimate requests, albeit with increased latency.

More details at "https://seanmonstar.com/blog/hyper-http2-continuation-flood/.

Patches available for 0.4.x and 0.3.x versions.

See advisory page for additional details.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

0 participants