A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests.
The product does not properly control the allocation and maintenance of a limited resource.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://hhvm.com/blog/2018/05/04/hhvm-3.25.3.html | vendor advisory |
https://github.com/facebook/hhvm/commit/4cb57dd753a339654ca464c139db9871fe961d56 | third party advisory patch |