moby/vendor
Sebastiaan van Stijn d66589496e
vendor: golang.org/x/net v0.23.0
full diff: https://github.com/golang/net/compare/v0.22.0...v0.23.0

Includes a fix for CVE-2023-45288, which is also addressed in go1.22.2
and go1.21.9;

> http2: close connections when receiving too many headers
>
> Maintaining HPACK state requires that we parse and process
> all HEADERS and CONTINUATION frames on a connection.
> When a request's headers exceed MaxHeaderBytes, we don't
> allocate memory to store the excess headers but we do
> parse them. This permits an attacker to cause an HTTP/2
> endpoint to read arbitrary amounts of data, all associated
> with a request which is going to be rejected.
>
> Set a limit on the amount of excess header frames we
> will process before closing a connection.
>
> Thanks to Bartek Nowotarski for reporting this issue.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2024-04-03 20:42:29 +02:00
..
cloud.google.com/go vendor: google.golang.org/genproto/googleapis/rpc 49dd2c1f3d0b 2024-02-12 09:25:26 +01:00
code.cloudfoundry.org/clock Vendor dependency cycle-free swarmkit 2024-02-28 09:46:45 -05:00
dario.cat/mergo vendor: containerd v1.7.12, and switch to dario.cat/mergo v1.0.0 2024-01-12 18:09:24 +01:00
github.com Merge pull request #47443 from corhere/cnmallocator/lift-n-shift 2024-03-21 12:29:46 -07:00
go.etcd.io vendor: go.etcd.io/bbolt v1.3.9 2024-02-27 18:24:01 +01:00
go.opencensus.io vendor: cloud.google.com/go/logging v1.7.0 2023-07-19 18:05:59 +02:00
go.opentelemetry.io vendor: github.com/moby/buildkit v0.13.0-rc2 2024-02-27 11:26:07 +01:00
go.uber.org vendor: go.uber.org/zap v1.21.0 2022-11-23 18:16:41 +01:00
golang.org/x vendor: golang.org/x/net v0.23.0 2024-04-03 20:42:29 +02:00
google.golang.org vendor: google.golang.org/protobuf v1.33.0, github.com/golang/protobuf v1.5.4 2024-03-14 13:12:54 +01:00
gopkg.in Vendor dependency cycle-free swarmkit 2024-02-28 09:46:45 -05:00
gotest.tools/v3 vendor: gotest.tools/v3 v3.5.1 2023-10-18 14:37:07 +02:00
k8s.io/klog/v2 vendor: k8s.io/klog/v2 v2.90.1 2023-07-19 18:06:01 +02:00
resenje.org/singleflight vendor: resenje.org/singleflight v0.4.1 2023-12-12 16:07:13 +01:00
sigs.k8s.io/yaml Update vendoring 2023-05-16 17:11:09 +02:00
tags.cncf.io/container-device-interface Update container-device-interface to v0.6.2 2023-11-04 01:00:19 +01:00
modules.txt vendor: golang.org/x/net v0.23.0 2024-04-03 20:42:29 +02:00