• CVE-2025-8671

发布时间: 2025年9月5日

修改时间: 2025年9月12日

概要

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Network
CVSS评分 N/A 7.5
Attack Complexity Low
Privileges Required None
Scope Unchanged
Integrity None
User Interaction None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2868 varnish security update 2025年9月12日
KylinSec-SA-2025-2869 varnish security update 2025年9月24日
KylinSec-SA-2025-2893 lighttpd security update 2025年9月29日
KylinSec-SA-2025-2897 varnish security update 2025年9月18日

影响产品

产品 状态
KY3.4-5A lighttpd Fixed
V6 lighttpd Fixed
KY3.5.3 lighttpd Fixed
KY3.5.2 lighttpd Fixed