已开启
backport net/http: raise an error when a http2 header frame is malformed #558
fortunate-lee创建于 2025年11月11日
backport net/http: raise an error when a http2 header frame is malformed #558
已开启
fortunate-lee创建于 2025年11月11日
从refs/pull/558/head合入到openEuler-24.03-LTS-SP2
共 2 个文件变更+51-1
@@ -0,0 +1,43 @@
1+From 987589dc7dbfe5967f3cddf81dd298e91fd3c85b Mon Sep 17 00:00:00 2001
2+From: Jonathan KUMA <jonathan.kuma@gmail.com>
3+Date: Thu, 6 Nov 2025 14:51:41 +0100
F
Ffuowang2025年11月12日

上游补丁,请保留原始patch头部信息

likedislike
4+Subject: [PATCH] net-http raise an error when a http2 header frame is
5+ malformed
6+ 
7+Fixes #31986
8+---
9+ src/net/http/h2_bundle.go | 11 ++++++++++-
10+ 1 file changed, 10 insertions(+), 1 deletion(-)
11+ 
12+diff --git a/src/net/http/h2_bundle.go b/src/net/http/h2_bundle.go
13+index 5ad0c28..5356eef 100644
14+--- a/src/net/http/h2_bundle.go
15++++ b/src/net/http/h2_bundle.go
16+@@ -1875,6 +1875,10 @@ func (fr *http2Framer) ErrorDetail() error {
17+ // sends a frame that is larger than declared with SetMaxReadFrameSize.
18+ var http2ErrFrameTooLarge = errors.New("http2: frame too large")
19+
20++// ErrFrameHeadersMalformed is returned from Framer.ReadFrame when the
21++// peer sends a http2FrameHeaders frame with a malformed header block.
22++var http2ErrFrameHeadersMalformed = errors.New("http2: malformed header frame")
23++
24+ // terminalReadFrameError reports whether err is an unrecoverable
25+ // error from ReadFrame and no other frames should be read.
26+ func http2terminalReadFrameError(err error) bool {
27+@@ -1924,7 +1928,12 @@ func (fr *http2Framer) ReadFrame() (http2Frame, error) {
28+ fr.debugReadLoggerf("http2: Framer %p: read %v", fr, http2summarizeFrame(f))
29+ }
30+ if fh.Type == http2FrameHeaders && fr.ReadMetaHeaders != nil {
31+- return fr.readMetaFrame(f.(*http2HeadersFrame))
32++ hf, ok := f.(*http2HeadersFrame)
33++ if !ok {
34++ return nil, http2ErrFrameHeadersMalformed
35++ }
36++
37++ return fr.readMetaFrame(hf)
38+ }
39+ return f, nil
40+ }
41+--
42+2.33.0
43+ 
@@ -66,7 +66,7 @@
66 66 
67Name: golang67Name: golang
68Version: 1.21.468Version: 1.21.4
69-Release: 3769+Release: 38
70Summary: The Go Programming Language70Summary: The Go Programming Language
71License: BSD and Public Domain71License: BSD and Public Domain
72URL: https://golang.org/72URL: https://golang.org/
@@ -156,6 +156,7 @@ Patch6033: backport-0033-CVE-2025-47907-database-sql-avoid-closing-Rows-while-sc
156Patch6034: backport-0034-CVE-2025-47906-os-exec-fix-incorrect-expansion-of-.-and-.-in-LookPa.patch156Patch6034: backport-0034-CVE-2025-47906-os-exec-fix-incorrect-expansion-of-.-and-.-in-LookPa.patch
157Patch6035: backport-0035-CVE-2025-4674-disable-support-for-multiple-vcs-in-one-module.patch157Patch6035: backport-0035-CVE-2025-4674-disable-support-for-multiple-vcs-in-one-module.patch
158Patch6036: backport-0036-CVE-2025-22871-net-http-reject-newlines-in-.patch158Patch6036: backport-0036-CVE-2025-22871-net-http-reject-newlines-in-.patch
159+Patch6037: backport-0037-net-http-raise-an-error-when-a-http2-header-frame-is.patch
159 160 
160# Part 8001 ~ 8999161# Part 8001 ~ 8999
161# Developed optimization features162# Developed optimization features
@@ -401,6 +402,12 @@ fi
401%files devel -f go-tests.list -f go-misc.list -f go-src.list402%files devel -f go-tests.list -f go-misc.list -f go-src.list
402 403 
403%changelog404%changelog
405+* Wed Nov 12 2025 lijian <lijian01@kylinos.cn> - 1.21.4-38
406+- Type:bugfix
407+- bug:76199
408+- SUG:NA
409+- DESC: net/http: raise an error when a http2 header frame is malformed
410+ 
404* Mon Sep 15 2025 songliyang <songliyang@kylinos.cn> - 1.21.4-37411* Mon Sep 15 2025 songliyang <songliyang@kylinos.cn> - 1.21.4-37
405- Type:CVE412- Type:CVE
406- CVE:CVE-2025-22871413- CVE:CVE-2025-22871