漏洞描述
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
support.apple.comhttps://support.apple.com/kb/HT214119↗httpd.apache.orghttps://httpd.apache.org/security/vulnerabilities_24.html↗seclists.orghttp://seclists.org/fulldisclosure/2024/Jul/18↗www.openwall.comhttps://www.openwall.com/lists/oss-security/2024/04/03/16↗www.openwall.comhttp://www.openwall.com/lists/oss-security/2024/04/04/4↗