An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).
{
"binaries": [
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+default-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+futures-cpupool-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+net2-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+runtime-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+tokio-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+tokio-executor-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+tokio-reactor-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+tokio-tcp-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+tokio-threadpool-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper+tokio-timer-dev"
},
{
"binary_version": "0.12.35-1",
"binary_name": "librust-hyper-dev"
}
]
}