Closed
Description
In CVE-2021-44716, the reference URL std (and possibly others) refers to something in Go.
module: std
package: std
description: |
net/http in Go before 1.16.12 and 1.17.x before 1.17.5 allows uncontrolled memory consumption in the header canonicalization cache via HTTP/2 requests.
cves:
- CVE-2021-44716
links:
context:
- https://groups.google.com/g/golang-announce/c/hcmEScgc00k
- https://lists.debian.org/debian-lts-announce/2022/01/msg00016.html
- https://lists.debian.org/debian-lts-announce/2022/01/msg00017.html
- https://security.netapp.com/advisory/ntap-20220121-0002/
See doc/triage.md for instructions on how to triage this report.