Collected research
A story of leaking uninitialized memory from Fastly
A bug in the H2O web server's HTTP/3 handling: a RESET_STREAM frame makes the Quicly library forget which byte ranges of a request body actually arrived, so H2O forwards the uninitialised remainder of its receive buffer to the upstream. A crafted QUIC datagram thus reads other users' requests and responses out of a Fastly node's memory.
Record
- Researcher
- Emil Lerner and @emil_lerner
- Published by
- Medium
- Date
- Topic
- Other
In the archive
Related sources
- H2O vendor advisory Advisory
Tags
This page is the archive's own catalogue record. The research is the work of Emil Lerner and @emil_lerner, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .