Skip to content

netty: Limit number of frames client can cause server to enqueue#6056

Merged
ejona86 merged 1 commit intogrpc:masterfrom
ejona86:ctrlframe-limit
Aug 13, 2019
Merged

netty: Limit number of frames client can cause server to enqueue#6056
ejona86 merged 1 commit intogrpc:masterfrom
ejona86:ctrlframe-limit

Conversation

@ejona86
Copy link
Copy Markdown
Member

@ejona86 ejona86 commented Aug 13, 2019

Http2ControlFrameLimitEncoder is from Netty. It is copied here as a
temporary measure until we upgrade to the version of Netty that includes
the class.

See CVE-2019-9515

Http2ControlFrameLimitEncoder is from Netty. It is copied here as a
temporary measure until we upgrade to the version of Netty that includes
the class.
@ejona86 ejona86 changed the title Limit number of frames client can cause server to enqueue netty: Limit number of frames client can cause server to enqueue Aug 13, 2019
@ejona86 ejona86 merged commit 9fcfb5b into grpc:master Aug 13, 2019
@ejona86 ejona86 deleted the ctrlframe-limit branch August 13, 2019 17:24
@lock lock bot locked as resolved and limited conversation to collaborators Nov 11, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants