漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
h2o: musl libc stack overflow (QPACK)
Vulnerability Description
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-stack buffer as large as approximately 800 KB by calling alloca, which exceeds the default pthread stack size used by musl libc and causes the h2o server to crash with a segmentation fault while touching the guard page. This issue is fixed in commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的内存分配
Vulnerability Title
h2o 资源管理错误漏洞
Vulnerability Description
h2o是H2O公司开源的一款新一代HTTP服务器。 h2o存在资源管理错误漏洞,该漏洞源于当处理HTTP/3对端发送的QPACK指令时,lib/http3/qpack.c可能通过alloca分配约800KB的栈上缓冲区,超出musl libc默认pthread栈大小,导致触碰保护页时服务崩溃。
CVSS Information
N/A
Vulnerability Type
N/A