h2o
cpe:2.3:a:h2o:h2o:*:*:*:*:*:*:*, +1 more
- <= 11b0cfa
A denial-of-service vulnerability has been identified in the h2o HTTP server, which supports HTTP/1.x, HTTP/2, and HTTP/3. The issue arises when the server allocates memory for file paths using the alloca function, potentially leading to stack overflow. This vulnerability affects h2o versions prior to the patch in commit 6b5370d. When the memory allocation exceeds the default pthread stack limit of 128KB in musl libc, the server crashes with a segmentation fault while accessing the guard page.
Exploitation of this vulnerability causes the h2o server to crash, leading to a segmentation fault and a denial-of-service condition.
Users can update to h2o version 6b5370d or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.