moby/vendor/golang.org/x/net
Sebastiaan van Stijn d66589496e
vendor: golang.org/x/net v0.23.0
full diff: https://github.com/golang/net/compare/v0.22.0...v0.23.0

Includes a fix for CVE-2023-45288, which is also addressed in go1.22.2
and go1.21.9;

> http2: close connections when receiving too many headers
>
> Maintaining HPACK state requires that we parse and process
> all HEADERS and CONTINUATION frames on a connection.
> When a request's headers exceed MaxHeaderBytes, we don't
> allocate memory to store the excess headers but we do
> parse them. This permits an attacker to cause an HTTP/2
> endpoint to read arbitrary amounts of data, all associated
> with a request which is going to be rejected.
>
> Set a limit on the amount of excess header frames we
> will process before closing a connection.
>
> Thanks to Bartek Nowotarski for reporting this issue.

Signed-off-by: Sebastiaan van Stijn <github@gone.nl>
2024-04-03 20:42:29 +02:00
..
bpf vendor: golang.org/x/net v0.1.0 2022-11-09 13:50:51 +01:00
context vendor: golang.org/x/net v0.18.0 2024-01-29 18:49:40 +01:00
http/httpguts vendor: golang.org/x/net v0.0.0-20220906165146-f3363e06e74c 2022-09-06 22:50:51 +02:00
http2 vendor: golang.org/x/net v0.23.0 2024-04-03 20:42:29 +02:00
idna vendor: golang.org/x/net v0.18.0 2024-01-29 18:49:40 +01:00
internal vendor: golang.org/x/net v0.18.0 2024-01-29 18:49:40 +01:00
ipv4 vendor: golang.org/x/net v0.18.0 2024-01-29 18:49:40 +01:00
ipv6 vendor: golang.org/x/net v0.18.0 2024-01-29 18:49:40 +01:00
trace vendor: golang.org/x/net v0.7.0 2023-02-14 21:00:09 +01:00
websocket vendor: golang.org/x/net v0.22.0, golang.org/x/crypto v0.21.0 2024-04-03 20:38:05 +02:00
LICENSE project: use vndr for vendoring 2016-11-03 15:31:46 -07:00
PATENTS project: use vndr for vendoring 2016-11-03 15:31:46 -07:00