Blame SOURCES/varnish-6.0.8-CVE-2022-45060.patch

b41ec4
diff --git a/bin/varnishd/http2/cache_http2_hpack.c b/bin/varnishd/http2/cache_http2_hpack.c
b41ec4
index d432629..b0dacb9 100644
b41ec4
--- a/bin/varnishd/http2/cache_http2_hpack.c
b41ec4
+++ b/bin/varnishd/http2/cache_http2_hpack.c
b41ec4
@@ -93,18 +93,25 @@ static h2_error
b41ec4
 h2h_addhdr(struct http *hp, char *b, size_t namelen, size_t len)
b41ec4
 {
b41ec4
 	/* XXX: This might belong in cache/cache_http.c */
b41ec4
+	const char *b0;
b41ec4
 	unsigned n;
b41ec4
+	int disallow_empty;
b41ec4
+	char *p;
b41ec4
+	int i;
b41ec4
 
b41ec4
 	CHECK_OBJ_NOTNULL(hp, HTTP_MAGIC);
b41ec4
 	AN(b);
b41ec4
 	assert(namelen >= 2);	/* 2 chars from the ': ' that we added */
b41ec4
 	assert(namelen <= len);
b41ec4
+	
b41ec4
+	disallow_empty = 0;
b41ec4
 
b41ec4
 	if (len > UINT_MAX) {	/* XXX: cache_param max header size */
b41ec4
 		VSLb(hp->vsl, SLT_BogoHeader, "Header too large: %.20s", b);
b41ec4
 		return (H2SE_ENHANCE_YOUR_CALM);
b41ec4
 	}
b41ec4
 
b41ec4
+	b0 = b;
b41ec4
 	if (b[0] == ':') {
b41ec4
 		/* Match H/2 pseudo headers */
b41ec4
 		/* XXX: Should probably have some include tbl for
b41ec4
@@ -113,10 +120,24 @@ h2h_addhdr(struct http *hp, char *b, size_t namelen, size_t len)
b41ec4
 			b += namelen;
b41ec4
 			len -= namelen;
b41ec4
 			n = HTTP_HDR_METHOD;
b41ec4
+			disallow_empty = 1;
b41ec4
+
b41ec4
+			/* First field cannot contain SP or CTL */
b41ec4
+			for (p = b, i = 0; i < len; p++, i++) {
b41ec4
+				if (vct_issp(*p) || vct_isctl(*p))
b41ec4
+					return (H2SE_PROTOCOL_ERROR);
b41ec4
+			}
b41ec4
 		} else if (!strncmp(b, ":path: ", namelen)) {
b41ec4
 			b += namelen;
b41ec4
 			len -= namelen;
b41ec4
 			n = HTTP_HDR_URL;
b41ec4
+			disallow_empty = 1;
b41ec4
+
b41ec4
+			/* Second field cannot contain LWS or CTL */
b41ec4
+			for (p = b, i = 0; i < len; p++, i++) {
b41ec4
+				if (vct_islws(*p) || vct_isctl(*p))
b41ec4
+					return (H2SE_PROTOCOL_ERROR);
b41ec4
+			}
b41ec4
 		} else if (!strncmp(b, ":scheme: ", namelen)) {
b41ec4
 			/* XXX: What to do about this one? (typically
b41ec4
 			   "http" or "https"). For now set it as a normal
b41ec4
@@ -124,6 +145,15 @@ h2h_addhdr(struct http *hp, char *b, size_t namelen, size_t len)
b41ec4
 			b++;
b41ec4
 			len-=1;
b41ec4
 			n = hp->nhd;
b41ec4
+
b41ec4
+			for (p = b + namelen, i = 0; i < len-namelen;
b41ec4
+			    p++, i++) {
b41ec4
+				if (vct_issp(*p) || vct_isctl(*p))
b41ec4
+					return (H2SE_PROTOCOL_ERROR);
b41ec4
+			}
b41ec4
+
b41ec4
+			if (!i)
b41ec4
+				return (H2SE_PROTOCOL_ERROR);
b41ec4
 		} else if (!strncmp(b, ":authority: ", namelen)) {
b41ec4
 			b+=6;
b41ec4
 			len-=6;
b41ec4
@@ -160,6 +190,13 @@ h2h_addhdr(struct http *hp, char *b, size_t namelen, size_t len)
b41ec4
 	hp->hd[n].b = b;
b41ec4
 	hp->hd[n].e = b + len;
b41ec4
 
b41ec4
+	if (disallow_empty && !Tlen(hp->hd[n])) {
b41ec4
+		VSLb(hp->vsl, SLT_BogoHeader,
b41ec4
+		    "Empty pseudo-header %.*s",
b41ec4
+		    (int)namelen, b0);
b41ec4
+		return (H2SE_PROTOCOL_ERROR);
b41ec4
+	}
b41ec4
+
b41ec4
 	return (0);
b41ec4
 }
b41ec4