FlawAtlas
Search the atlas
UBUNTU-CVE-2022-41717 Moderate

UBUNTU-CVE-2022-41717

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

Exploit probability Not scored
Published December 8, 2022
Required by Not available
Last source change May 20, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS golang-1.10

1 explicit affected versions

Ubuntu:16.04:LTS golang-1.10

2 explicit affected versions

Ubuntu:16.04:LTS golang-1.6

10 explicit affected versions

Ubuntu:18.04:LTS golang-1.10

8 explicit affected versions

Ubuntu:18.04:LTS golang-1.18

1 explicit affected versions

Ubuntu:18.04:LTS golang-1.8

2 explicit affected versions

Ubuntu:18.04:LTS golang-1.9

5 explicit affected versions

Ubuntu:20.04:LTS golang-1.13

9 explicit affected versions

Ubuntu:20.04:LTS golang-1.14

9 explicit affected versions

Ubuntu:20.04:LTS golang-1.16

1 explicit affected versions

Ubuntu:20.04:LTS golang-1.18

1 explicit affected versions

Ubuntu:22.04:LTS golang-1.13

2 explicit affected versions

Ubuntu:22.04:LTS golang-1.17

6 explicit affected versions

Ubuntu:22.04:LTS golang-1.18

6 explicit affected versions

Ubuntu:Pro:16.04:LTS golang-1.13

3 explicit affected versions

Ubuntu:Pro:18.04:LTS golang-1.13

3 explicit affected versions

Ubuntu:Pro:18.04:LTS golang-1.16

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2022-41717

An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is capped, an attacker sending very large keys can cause the server to allocate approximately 64 MiB per open connection.

View original source

05 / REFERENCES

Further evidence