PT-2022-12207 · Go+8 · Go+8

Murakmii

·

Published

2021-12-09

·

Updated

2024-06-15

·

CVE-2021-44716

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Go versions prior to 1.16.12 Go versions 1.17.x prior to 1.17.5
Description The issue allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests, potentially causing unbounded memory growth in servers accepting HTTP/2 requests.
Recommendations For Go versions prior to 1.16.12, update to version 1.16.12 or later. For Go versions 1.17.x prior to 1.17.5, update to version 1.17.5 or later.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:5160
ALSA-2022:0001
ALT-PU-2021-3504
ALT-PU-2021-3513
ALT-PU-2022-1243
ALT-PU-2022-2873
AZL-31978
AZL-33564
AZL-33571
AZL-33577
AZL-33581
AZL-33585
AZL-33592
AZL-33597
AZL-33604
AZL-33607
AZL-33612
AZL-33613
AZL-33616
AZL-33624
AZL-33627
AZL-33635
AZL-33638
AZL-33641
AZL-34836
AZL-35004
AZL-35013
AZL-35037
AZL-35123
AZL-39672
AZL-43909
AZL-45165
AZL-7125
BIT-GOLANG-2021-44716
CESA-2021_5160
CESA-2022_0001
CVE-2021-44716
DLA-2891-1
DLA-2892-1
DLA-3395-1
DLA-3395-2
GHSA-VC3P-29H2-GPCP
GO-2022-0288
MGASA-2021-0587
OESA-2022-1499
OPENSUSE-SU-2021:1626-1
OPENSUSE-SU-2021:4169-1
OPENSUSE-SU-2021:4186-1
OPENSUSE-SU-2021_1626-1
OPENSUSE-SU-2021_4169-1
OPENSUSE-SU-2021_4186-1
OPENSUSE-SU-2023:0018-1
OPENSUSE-SU-2023_0018-1
OPENSUSE-SU-2024:11671-1
OPENSUSE-SU-2024:11672-1
RHSA-2021:5160
RHSA-2021:5176
RHSA-2021_5160
RHSA-2022:0001
RHSA-2022:0002
RHSA-2022:0055
RHSA-2022:0237
RHSA-2022:0260
RHSA-2022:0557
RHSA-2022:0927
RHSA-2022:1056
RHSA-2022:1361
RHSA-2022:1628
RHSA-2022_0001
RHSA-2023:0407
RLSA-2021:5160
RLSA-2022:0001
SUSE-SU-2021:4169-1
SUSE-SU-2021:4186-1
SUSE-SU-2021_4169-1
SUSE-SU-2021_4186-1
SUSE-SU-2022:1729-1
SUSE-SU-2022:3338-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Go
Red Hat
Rocky Linux
Suse