Codex Discovered a Hidden HTTP/2 Bomb
blog.calif.io
Codex Discovered a Hidden HTTP/2 Bomb
1–8 of 8 posts
Re: Codex Discovered a Hidden HTTP/2 Bomb
#2This is already something that is known, and if you're able to be targeted by this (which is not the majority of users) configure your httpd differently.
Re: Codex Discovered a Hidden HTTP/2 Bomb
#3This appears to be fixed as of April (at least for Apache). [0].
[0] - https://github.com/nginx/nginx/commit/365694160a85229a7cb006...
Re: Codex Discovered a Hidden HTTP/2 Bomb
#4Re: Codex Discovered a Hidden HTTP/2 Bomb
#5Couldn’t simple fuzzing have found this?
Re: Codex Discovered a Hidden HTTP/2 Bomb
#6After reading the article, I can conclude that Codex discovered nothing new. This is already something that is known, and if you're able to be targeted by this (which is not the majority of users) configure your httpd differently.
Re: Codex Discovered a Hidden HTTP/2 Bomb
#7I was about to say, the bug here isn't in the protocol, it's that memory use isn't being counted & limited as it should... and, yeah.
I'm a bit surprised this happened to Apache, though. APR uses pool allocators. That should be easy enough to track and limit...
Re: Codex Discovered a Hidden HTTP/2 Bomb
#8After reading the article, I can conclude that Codex discovered nothing new. This is already something that is known, and if you're able to be targeted by this (which is not the majority of users) configure your httpd differently.
Apache and nginx maintainers implemented fixes one or two days after the author reported, so how do you mean this was known already?