Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 918413

Summary: <www-servers/caddy-2.7.5: http/2 rapid reset vulnerability
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: me, proxy-maint, zmedico
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://github.com/caddyserver/caddy/issues/5877
Whiteboard: B3 [glsa? cleanup]
Package list:
Runtime testing required: ---
Bug Depends on: 918414    
Bug Blocks: 915553    

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-11-24 18:40:44 UTC
CVE-2023-44487:

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Patch is in 2.7.5: https://github.com/caddyserver/caddy/commit/88b4fbf2444481a68af3ce86843cf6e3bb84c136

Please stabilize 2.7.5.