Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: resolve issue with CVE-2021-44716 #1349

Merged

Conversation

denis-tingaikin
Copy link
Member

Signed-off-by: Denis Tingaikin denis.tingajkin@xored.com

Description

	CVE-2021-44716 - (trivy) - (nsmgr, forwarder, NSE Remote VLAN):
		golang: net/http: limit growth of header canonicalization cache
		net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
		Package name: golang.org/x/net
		Installed version: v0.0.0-20211112202133-69e39bad7dc2
		Fixed version:     v0.0.0-20211209124913-491a49abca63

Issue link

How Has This Been Tested?

  • Added unit testing to cover
  • Tested manually
  • Tested by integration testing
  • [] Have not tested

Types of changes

  • Bug fix
  • New functionallity
  • Documentation
  • Refactoring
  • CI

@denis-tingaikin denis-tingaikin marked this pull request as draft September 9, 2022 15:44
@edwarnicke
Copy link
Member

LGTM :)

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
@denis-tingaikin denis-tingaikin marked this pull request as ready for review September 12, 2022 18:11
@edwarnicke edwarnicke merged commit e72a32c into networkservicemesh:main Sep 12, 2022
nsmbot pushed a commit to networkservicemesh/cmd-ipam-vl3 that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/sdk-kernel that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-registry-memory that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-registry-proxy-dns that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nsmgr-proxy that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nse-vfio that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-map-ip-k8s that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nsmgr that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nse-remote-vlan that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-admission-webhook-k8s that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-cluster-info-k8s that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
nsmbot pushed a commit to networkservicemesh/cmd-nsc-init that referenced this pull request Sep 12, 2022
…k@main

PR link: networkservicemesh/sdk#1349

Commit: e72a32c
Author: Denis Tingaikin
Date: 2022-09-12 21:28:21 +0300
Message:
  - fix: resolve issue with CVE-2021-44716 (#1349)
* Resolve issue with CVE-2021-44716

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>

* update otel to avoid  golang.org/x/net v0.0.0-20211112202133-69e39bad7dc2

Signed-off-by: Denis Tingaikin <denis.tingajkin@xored.com>
Signed-off-by: NSMBot <nsmbot@networkservicmesh.io>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants