Уязвимость в http2-модуле из состава Node.js

The developers of the Node.js server-side JavaScript platform have released corrective versions 12.22.4, 14.17.4, and 16.6.0, which partially address the vulnerability (CVE-2021-22930) in the http2 module (HTTP/2.0 client) that allows a process crash or potentially enables the execution of arbitrary code in the system when contacting a host controlled by an attacker.

The issue is caused by accessing a previously freed memory area when closing a connection after receiving RST_STREAM frames (stream reset) for streams that are performing intensive read operations that block writing. In the event of receiving an RST_STREAM frame without an error code, the http2 module additionally calls the cleanup procedure for already received data, from which the close handler is invoked again for the already closed stream, leading to a double release of data structures.

The discussion of the fix notes that the issue is not fully resolved and continues to manifest under slightly altered conditions in the published updates. The analysis showed that the fix addresses only one specific case — when the stream is in read mode, but does not account for other stream states (reading and paused, paused and certain types of writing).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster