Skip to content

Reject negative body size when parsing content headers (backport #2013) - #2014

Merged
acogoluegnes merged 1 commit into
v5.xfrom
mergify/bp/v5.x/pr-2013
Jul 8, 2026
Merged

acogoluegnes merged 1 commit into
v5.xfrom
mergify/bp/v5.x/pr-2013

Conversation

@mergify

@mergify mergify Bot commented Jul 8, 2026

Copy link
Copy Markdown

consumeHeaderFrame read the content header's body-size field as a signed long and only checked it against the configured maximum with bodySize >= maxBodyLength. A wire value with the high bit set decodes to a negative long, which always satisfies that comparison, bypassing the size check. The negative remainingBodyBytes then made the command complete with an empty body instead of throwing, so any body frames that followed were parsed as the start of a new command.

Reject negative body sizes the same way oversized ones are already rejected.

Add BrokenFramesTest#negativeBodySizeTriggersConnectionClosure.


This is an automatic backport of pull request #2013 done by Mergify.

consumeHeaderFrame read the content header's body-size field as a
signed long and only checked it against the configured maximum with
`bodySize >= maxBodyLength`. A wire value with the high bit set
decodes to a negative long, which always satisfies that comparison,
bypassing the size check. The negative remainingBodyBytes then made
the command complete with an empty body instead of throwing, so any
body frames that followed were parsed as the start of a new command.

Reject negative body sizes the same way oversized ones are already
rejected.

Add BrokenFramesTest#negativeBodySizeTriggersConnectionClosure.

(cherry picked from commit f2f0a25)
@acogoluegnes acogoluegnes added this to the 5.34.0 milestone Jul 8, 2026
@acogoluegnes
acogoluegnes merged commit e62665b into v5.x Jul 8, 2026
4 of 6 checks passed
@acogoluegnes
acogoluegnes deleted the mergify/bp/v5.x/pr-2013 branch July 8, 2026 16:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant