Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
h2o: musl libc stack overflow (QPACK)
Vulnerability Description
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-stack buffer as large as approximately 800 KB by calling alloca, which exceeds the default pthread stack size used by musl libc and causes the h2o server to crash with a segmentation fault while touching the guard page. This issue is fixed in commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的内存分配
Vulnerability Title
h2o 资源管理错误漏洞
Vulnerability Description
h2o是H2O公司开源的一款新一代HTTP服务器。 h2o存在资源管理错误漏洞,该漏洞源于当处理HTTP/3对端发送的QPACK指令时,lib/http3/qpack.c可能通过alloca分配约800KB的栈上缓冲区,超出musl libc默认pthread栈大小,导致触碰保护页时服务崩溃。
CVSS Information
N/A
Vulnerability Type
N/A