DockerCLI/vendor/golang.org/x/net/http2
Sebastiaan van Stijn 02b482013c
vendor: golang.org/x/net v0.23.0
full diff: https://github.com/golang/net/compare/v0.22.0...v0.23.0

Includes a fix for CVE-2023-45288, which is also addressed in go1.22.2
and go1.21.9;

> http2: close connections when receiving too many headers
>
> Maintaining HPACK state requires that we parse and process
> all HEADERS and CONTINUATION frames on a connection.
> When a request's headers exceed MaxHeaderBytes, we don't
> allocate memory to store the excess headers but we do
> parse them. This permits an attacker to cause an HTTP/2
> endpoint to read arbitrary amounts of data, all associated
> with a request which is going to be rejected.
>
> Set a limit on the amount of excess header frames we
> will process before closing a connection.
>
> Thanks to Bartek Nowotarski for reporting this issue.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
(cherry picked from commit 5fcbbde4b9)
Signed-off-by: Austin Vazquez <macedonv@amazon.com>
2024-07-22 17:01:43 +00:00
..
hpack vendor: golang.org/x/net v0.7.0 2023-03-15 01:42:00 +01:00
.gitignore vendor with go mod 2021-12-16 21:16:01 +01:00
ascii.go vendor: golang.org/x/net v0.0.0-20211216030914-fe4d6282115f 2022-03-16 15:21:39 +01:00
ciphers.go Bump moby version (and its dependencies) 2018-06-08 11:26:10 +02:00
client_conn_pool.go vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 23:14:47 +02:00
databuffer.go vendor: golang.org/x/net v0.19.0 2024-01-08 10:55:39 +01:00
errors.go vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 23:14:47 +02:00
flow.go vendor: golang.org/x/net v0.7.0 2023-03-15 01:42:00 +01:00
frame.go vendor: golang.org/x/net v0.23.0 2024-07-22 17:01:43 +00:00
gotrack.go Add vendor 2017-04-17 18:12:58 -04:00
headermap.go vendor: golang.org/x/net v0.4.0 2022-12-22 23:00:49 +01:00
http2.go vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 23:14:47 +02:00
pipe.go vendor: golang.org/x/net v0.23.0 2024-07-22 17:01:43 +00:00
server.go vendor: golang.org/x/net v0.23.0 2024-07-22 17:01:43 +00:00
testsync.go vendor: golang.org/x/net v0.23.0 2024-07-22 17:01:43 +00:00
transport.go vendor: golang.org/x/net v0.23.0 2024-07-22 17:01:43 +00:00
write.go vendor: golang.org/x/net v0.0.0-20211216030914-fe4d6282115f 2022-03-16 15:21:39 +01:00
writesched.go vendor: golang.org/x/net v0.17.0 2023-10-13 20:56:02 +02:00
writesched_priority.go vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 23:14:47 +02:00
writesched_random.go vendor: golang.org/x/net v0.0.0-20211216030914-fe4d6282115f 2022-03-16 15:21:39 +01:00
writesched_roundrobin.go vendor: golang.org/x/net v0.17.0 2023-10-13 20:56:02 +02:00