Skip to content

Cap ReadFrame allocations from peer-declared length - #226

Open
AshSgDe29071999 wants to merge 1 commit into
gobwas:masterfrom
AshSgDe29071999:fix/readframe-max-payload
Open

AshSgDe29071999 wants to merge 1 commit into
gobwas:masterfrom
AshSgDe29071999:fix/readframe-max-payload

Conversation

@AshSgDe29071999

Copy link
Copy Markdown

ReadFrame allocated make([]byte, Header.Length) with no limit, so a post-handshake peer could declare a huge payload and OOM the process.

Honor MaxFramePayloadSize (default 32MiB). Set it to 0 to restore the old unlimited behavior. wsutil.ReadMessage uses the same cap.

Fixes #223

Test

go test . -run TestReadFrameRejectsOversizedPayload -count=1

ReadFrame allocated make([]byte, Header.Length) with no limit, so a
post-handshake peer could declare a huge payload and OOM the process.
Honor MaxFramePayloadSize (default 32MiB).

See gobwas#223
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security] ReadFrame/ReadMessage allocate peer-declared frame length, MaxFrameSize defaults 0 -> OOM DoS (read.go:116)

1 participant