CHANGES and release notes for CVE-2022-2881 [GL #3493]

This commit is contained in:
Evan Hunt
2022-08-16 16:26:02 -07:00
committed by Michał Kępień
parent 47e9fa981e
commit 430ee6c427
2 changed files with 11 additions and 1 deletions

View File

@@ -6,7 +6,12 @@
5959. [placeholder]
5958. [placeholder]
5958. [security] When an HTTP connection was reused to get
statistics from the stats channel, and zlib
compression was in use, each successive
response sent larger and larger blocks of memory,
potentially reading past the end of the allocated
buffer. (CVE-2022-2881) [GL #3493]
5957. [security] Prevent excessive resource use while processing large
delegations. (CVE-2022-2795) [GL #3394]

View File

@@ -24,6 +24,11 @@ Security Fixes
Bremler-Barr & Shani Stajnrod from Reichman University for bringing
this vulnerability to our attention. :gl:`#3394`
- When an HTTP connection was reused to request statistics from the
stats channel, the content length of successive responses could grow
in size past the end of the allocated buffer. This has been fixed.
(CVE-2022-2881) :gl:`#3493`
Known Issues
~~~~~~~~~~~~