transport: restrict memory overhead of buffering small data frames - #9331
Merged
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #9331 +/- ##
==========================================
- Coverage 83.07% 83.06% -0.01%
==========================================
Files 423 423
Lines 35233 35266 +33
==========================================
+ Hits 29270 29295 +25
- Misses 4449 4451 +2
- Partials 1514 1520 +6
🚀 New features to boost your workflow:
|
easwars
approved these changes
Aug 19, 2026
This was referenced Aug 19, 2026
arjan-bal
added a commit
that referenced
this pull request
Aug 19, 2026
Original PR: #9331 RELEASE NOTES: * transport: restrict memory overhead of buffering small data frames.
arjan-bal
added a commit
that referenced
this pull request
Aug 19, 2026
Original PR: #9331 RELEASE NOTES: N/A
eleboucher
pushed a commit
to eleboucher/runner-k8s-plugin
that referenced
this pull request
Aug 19, 2026
…(#83) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.0` → `v1.83.1` |  |  | --- ### Release Notes <details> <summary>grpc/grpc-go (google.golang.org/grpc)</summary> ### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1 [Compare Source](grpc/grpc-go@v1.83.0...v1.83.1) ### Security - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) ### Performance - transport: Restrict memory overhead of buffering small data frames. ([#​9331](grpc/grpc-go#9331)) ### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0 [Compare Source](grpc/grpc-go@v1.82.1...v1.83.0) ### Security - server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. - xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#​9223](grpc/grpc-go#9223)) ### New Features - xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#​9133](grpc/grpc-go#9133)) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#​9145](grpc/grpc-go#9145)) - authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#​9142](grpc/grpc-go#9142)) - Special Thanks: [@​hnefatl](https://github.com/hnefatl) - xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#​9119](grpc/grpc-go#9119)) - xds: Add support for xDS-based HTTP CONNECT proxies. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#​9151](grpc/grpc-go#9151)) - xds: Add support for `contains_match` in route header matchers. ([#​9223](grpc/grpc-go#9223)) ### Bug Fixes - credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#​9197](grpc/grpc-go#9197)) - grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#​9255](grpc/grpc-go#9255)) - Special Thanks: [@​Yusufihsangorgel](https://github.com/Yusufihsangorgel) ### [`v1.82.1`](https://github.com/grpc/grpc-go/releases/tag/v1.82.1): Release 1.82.1 [Compare Source](grpc/grpc-go@v1.82.0...v1.82.1) ### Security - server: Stop reading from the connection when flooded by HTTP/2 frames. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Paris) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xMDEuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjMxLjAiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbInR5cGUvbWlub3IiXX0=--> Reviewed-on: https://git.erwanleboucher.dev/eleboucher/runner-k8s-plugin/pulls/83
nschloe
pushed a commit
to live-clones/forgejo
that referenced
this pull request
Sep 3, 2026
…/forgejo) (#14216) This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [google.golang.org/grpc](https://github.com/grpc/grpc-go) | `v1.82.1` → `v1.83.1` |  |  | --- >⚠️ **Warning** > > Some dependencies could not be looked up. Check the [Dependency Dashboard](issues/2779) for more information. --- ### gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation [CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) / [GHSA-vp52-pcj8-j9qc](GHSA-vp52-pcj8-j9qc) <details> <summary>More information</summary> #### Details ##### Impact An unauthenticated remote attacker can initiate a gRPC stream and purposefully fragment their payload into millions of tiny (e.g., 1-byte) HTTP/2 DATA frames. Even if the total payload volume falls within the configured connection and stream flow-control windows, each independent fragment incurs memory overhead due to internal tracking structures and queue allocation. Repeated fragmentation massively inflates the heap space consumed by the stream. An attacker multiplexing multiple concurrent streams can exhaust the memory bounds of the runtime, forcing a runtime panic or OutOfMemory condition and leading to a remote Denial of Service (DoS). ##### Patches The change to fix this issue is merged in `master` and a patch release, 1.83.1, has been published that contains this fix. ##### Workarounds This vulnerability is mitigated by implementing receive buffer compaction. Consecutive small data buffers are automatically coalesced into larger buffers from a shared pool once the overhead is perceived to be excessive relative to actual payload data, drastically minimizing per-frame memory overheads. This behavior is enabled by default. A temporary escape hatch is provided via the environment variable `GRPC_GO_EXPERIMENTAL_ENABLE_RECEIVE_BUFFER_COMPACTION=false` to disable the feature if unforeseen issues arise, but it will be removed in a future release. #### Severity - CVSS Score: 8.7 / 10 (High) - Vector String: `CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N` #### References - [https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc](https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc) - [https://nvd.nist.gov/vuln/detail/CVE-2026-84304](https://nvd.nist.gov/vuln/detail/CVE-2026-84304) - [https://github.com/grpc/grpc-go/pull/9331](https://github.com/grpc/grpc-go/pull/9331) - [https://github.com/grpc/grpc-go/pull/9333](https://github.com/grpc/grpc-go/pull/9333) - [https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176](https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176) - [https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77](https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77) - [https://github.com/grpc/grpc-go](https://github.com/grpc/grpc-go) - [https://github.com/grpc/grpc-go/releases/tag/v1.83.1](https://github.com/grpc/grpc-go/releases/tag/v1.83.1) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-vp52-pcj8-j9qc) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Release Notes <details> <summary>grpc/grpc-go (google.golang.org/grpc)</summary> ### [`v1.83.1`](https://github.com/grpc/grpc-go/releases/tag/v1.83.1): Release 1.83.1 [Compare Source](grpc/grpc-go@v1.83.0...v1.83.1) ### Security - xds/rbac: Fix a bug where nested `Principal` or `Permission` rules with `:scheme` or `grpc-` prefixed header matchers were not rejected, which could cause DENY rules to fail open. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where the `host` header matcher was not being replaced with `:authority` in nested `Principal` or `Permission` rules. ([#​9258](grpc/grpc-go#9258)) - Special Thanks: [@​nvxbug](https://github.com/nvxbug) - xds/rbac: Fix a bug where a header matcher whose name was not lowercase, such as `X-Role`, matched no header, which could cause DENY rules to fail open. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `:scheme` or `grpc-` prefixed header matcher was accepted when its name was not lowercase. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) - xds/rbac: Fix a bug where a `Host` header matcher was not replaced with `:authority`. ([#​9332](grpc/grpc-go#9332)) - Special Thanks: [@​alimony](https://github.com/alimony) ### Performance - transport: Restrict memory overhead of buffering small data frames. ([#​9331](grpc/grpc-go#9331)) ### [`v1.83.0`](https://github.com/grpc/grpc-go/releases/tag/v1.83.0): Release 1.83.0 [Compare Source](grpc/grpc-go@v1.82.2...v1.83.0) ### Security - server: Stop reading from connections when flooded by HTTP/2 frames to mitigate resource exhaustion. The default value for this limit is 100 frames, excluding DATA and HEADERS, and may be changed by setting environment variable `GRPC_GO_EXPERIMENTAL_CONTROL_BUFFER_THROTTLE_LIMIT`. - xds/rbac: Support `Metadata` and `RequestedServerName` permissions matcher fields. If present in a DENY rule, previously these would be ignored and fail-open. - xds/rbac: Fix panic when parsing unsupported fields in `NotRule`/`NotId` permissions. - xds/rbac: Support the deprecated `source_ip` principal identifier by treating it as equivalent to `direct_remote_ip`. - xds: Fix panic when parsing route header matchers configured with empty `exact_match`, `prefix_match`, or `suffix_match` strings. ([#​9223](grpc/grpc-go#9223)) ### New Features - xds/googlec2p: Enable DirectPath over Interconnect support for on-premises clients via the `force-xds` target URI query parameter. ([#​9133](grpc/grpc-go#9133)) - xds: Enable xDS configuration to control which fields get propagated from ORCA backend metric reports to LRS load reports. ([#​9145](grpc/grpc-go#9145)) - authz: Add `OnPolicyUpdate` callback to `FileWatcherOptions` to notify when an authz policy is loaded or updated. ([#​9142](grpc/grpc-go#9142)) - Special Thanks: [@​hnefatl](https://github.com/hnefatl) - xds: Add support for the GCP Authentication HTTP Filter, which automatically fetches and attaches GCP Service Account Identity JWT tokens to outgoing RPCs. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_GCP_AUTHENTICATION_FILTER=true`. ([#​9119](grpc/grpc-go#9119)) - xds: Add support for xDS-based HTTP CONNECT proxies. - This feature can be enabled by setting environment variable `GRPC_EXPERIMENTAL_XDS_HTTP_CONNECT=true`. ([#​9151](grpc/grpc-go#9151)) - xds: Add support for `contains_match` in route header matchers. ([#​9223](grpc/grpc-go#9223)) ### Bug Fixes - credentials/alts: Fix panic when processing malformed frames by validating that the message frame length exceeds the message type field size. ([#​9197](grpc/grpc-go#9197)) - grpc: Fix compilation on Plan 9 targets (`GOOS=plan9`), broken since v1.81.0. ([#​9255](grpc/grpc-go#9255)) - Special Thanks: [@​Yusufihsangorgel](https://github.com/Yusufihsangorgel) ### [`v1.82.2`](https://github.com/grpc/grpc-go/releases/tag/v1.82.2): Release 1.82.2 [Compare Source](grpc/grpc-go@v1.82.1...v1.82.2) ### Security - server: Reject requests missing both `:authority` and `Host` headers with HTTP 400 and status `Internal`. ([#​9365](grpc/grpc-go#9365)) - Special Thanks: [@​winklemad](https://github.com/winklemad) </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41Mi4wIiwidXBkYXRlZEluVmVyIjoiNDQuNTIuMCIsInRhcmdldEJyYW5jaCI6InYxNi4wL2Zvcmdlam8iLCJsYWJlbHMiOlsiZGVwZW5kZW5jeS11cGdyYWRlIiwidGVzdC9ub3QtbmVlZGVkIl19--> Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/14216 Reviewed-by: Mathieu Fenniak <[email protected]>
dperny
added a commit
to dperny/docker
that referenced
this pull request
Sep 11, 2026
full diff: grpc/grpc-go@v1.80.0...v1.83.1 Fixes CVE-2026-84304 / GHSA-vp52-pcj8-j9qc, a heap-exhaustion denial of service. internal/transport/transport.go stored each fragmented HTTP/2 DATA frame as its own recvMsg in recvBuffer, so a peer sending millions of one-byte frames could exhaust process memory while staying inside the connection and stream flow-control windows. An unauthenticated remote peer could use concurrent multiplexed streams to force a panic or OOM. The fix is in v1.83.1 (grpc/grpc-go#9331); v1.83.0 and earlier are affected. grpc v1.83.1 raises the minimum version of several of its own dependencies, and hack/vendor.sh bumps those along with it. No module is added to or removed from the vendor tree; these are the only version changes: | module | from | to | | --- | --- | --- | | `cloud.google.com/go` | v0.120.0 | v0.123.0 | | `cloud.google.com/go/auth` | v0.15.0 | v0.18.2 | | `cloud.google.com/go/logging` | v1.13.0 | v1.13.1 | | `cloud.google.com/go/longrunning` | v0.6.6 | v0.8.0 | | `github.com/googleapis/enterprise-certificate-proxy` | v0.3.6 | v0.3.11 | | `github.com/googleapis/gax-go/v2` | v2.14.1 | v2.17.0 | | `go.opentelemetry.io/contrib/.../otelgrpc` | v0.60.0 | v0.61.0 | | `go.opentelemetry.io/contrib/.../otelhttp` | v0.60.0 | v0.61.0 | | `go.opentelemetry.io/otel` (+metric, sdk, trace) | v1.43.0 | v1.44.0 | | `golang.org/x/time` | v0.12.0 | v0.14.0 | | `google.golang.org/api` | v0.228.0 | v0.264.0 | | `google.golang.org/genproto` | 20250324211829 | 20260128011058 | | `google.golang.org/genproto/googleapis/{api,rpc}` | 20260401024825 | 20260526163538 | otelgrpc v0.61.0 removes the deprecated UnaryClientInterceptor and UnaryServerInterceptor constructors, which is why the preceding commit backports the migration to stats handlers. Signed-off-by: Drew Erny <[email protected]> Co-Authored-By: Claude Opus 5 <[email protected]>
dperny
added a commit
to dperny/docker
that referenced
this pull request
Sep 11, 2026
full diff: grpc/grpc-go@v1.80.0...v1.83.1 Fixes CVE-2026-84304 / GHSA-vp52-pcj8-j9qc, a heap-exhaustion denial of service. internal/transport/transport.go stored each fragmented HTTP/2 DATA frame as its own recvMsg in recvBuffer, so a peer sending millions of one-byte frames could exhaust process memory while staying inside the connection and stream flow-control windows. An unauthenticated remote peer could use concurrent multiplexed streams to force a panic or OOM. The fix is in v1.83.1 (grpc/grpc-go#9331); v1.83.0 and earlier are affected. grpc v1.83.1 raises the minimum version of several of its own dependencies, and hack/vendor.sh bumps those along with it. No module is added to or removed from the vendor tree; these are the only version changes: | module | from | to | | --- | --- | --- | | `cloud.google.com/go` | v0.120.0 | v0.123.0 | | `cloud.google.com/go/auth` | v0.15.0 | v0.18.2 | | `cloud.google.com/go/logging` | v1.13.0 | v1.13.1 | | `cloud.google.com/go/longrunning` | v0.6.6 | v0.8.0 | | `github.com/googleapis/enterprise-certificate-proxy` | v0.3.6 | v0.3.11 | | `github.com/googleapis/gax-go/v2` | v2.14.1 | v2.17.0 | | `go.opentelemetry.io/contrib/.../otelgrpc` | v0.60.0 | v0.61.0 | | `go.opentelemetry.io/contrib/.../otelhttp` | v0.60.0 | v0.61.0 | | `go.opentelemetry.io/otel` (+metric, sdk, trace) | v1.43.0 | v1.44.0 | | `golang.org/x/time` | v0.12.0 | v0.14.0 | | `google.golang.org/api` | v0.228.0 | v0.264.0 | | `google.golang.org/genproto` | 20250324211829 | 20260128011058 | | `google.golang.org/genproto/googleapis/{api,rpc}` | 20260401024825 | 20260526163538 | otelgrpc v0.61.0 removes the deprecated UnaryClientInterceptor and UnaryServerInterceptor constructors, which is why the preceding commit backports the migration to stats handlers. Signed-off-by: Drew Erny <[email protected]> Co-Authored-By: Claude Opus 5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
RELEASE NOTES: