https://bugzilla.redhat.com/show_bug.cgi?id=2530536

            Bug ID: 2530536
           Summary: CVE-2026-16028 perl-Protocol-HTTP2: Protocol::HTTP2:
                    Denial of Service via memory exhaustion from unremoved
                    closed streams [fedora-all]
           Product: Fedora
           Version: rawhide
            Status: NEW
        Whiteboard: {"flaws": ["8e643f53-8f58-4100-9ee1-cf878d9dff08"]}
         Component: perl-Protocol-HTTP2
          Keywords: Security, SecurityTracking
          Severity: high
          Priority: high
          Assignee: [email protected]
          Reporter: [email protected]
        QA Contact: [email protected]
                CC: [email protected], [email protected]
            Blocks: 2529576 (CVE-2026-16028)
  Target Milestone: ---
    Classification: Fedora



Disclaimer: Community trackers are created by Red Hat Product Security team on
a best effort basis. Package maintainers are required to ascertain if the flaw
indeed affects their package, before starting the update process.

Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via
closed streams that stream_state never removes from the connection stream
table.

When a stream reaches the CLOSED state, stream_state returns the concurrency
slot and clears most of the stream's keys, but the entry itself stays in the
connection stream table and nothing in the distribution removes it. Stream
identifiers increase monotonically, so a peer can open and close streams on one
connection indefinitely, each close leaving a residual entry that is retained
for the life of the connection.

SETTINGS_MAX_CONCURRENT_STREAMS does not bound this. That setting caps how many
streams are live at once and is enforced, while the growth is made of streams
the cap has already released, so it accumulates with concurrency never
exceeding one. The client keeps the same table and grows the same way against a
hostile server.

Measured against a server built on this module, roughly 920 bytes are retained
per closed stream for about 19 bytes on the wire, so 100,000 sequential streams
on one connection grow server resident memory by about 88 MiB. The streams are
ordinary requests that the application accepts and completes.



Referenced Bugs:

https://bugzilla.redhat.com/show_bug.cgi?id=2529576
[Bug 2529576] CVE-2026-16028 perl-Protocol-HTTP2: Protocol::HTTP2: Denial of
Service via memory exhaustion from unremoved closed streams
-- 
You are receiving this mail because:
You are on the CC list for the bug.
https://bugzilla.redhat.com/show_bug.cgi?id=2530536

Report this comment as SPAM: 
https://bugzilla.redhat.com/enter_bug.cgi?product=Bugzilla&format=report-spam&short_desc=Report%20of%20Bug%202530536%23c0

-- 
_______________________________________________
perl-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to