Skip to content

OCPBUGS-103732: CVE-2026-33814 openshift4/ose-prometheus-node-exporter-rhel9: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [openshift-4.19] - #215

Open
tonyxrmdavidson wants to merge 1 commit into
openshift:release-4.19from
tonyxrmdavidson:OCPBUGS-103732-CVE-2026-33814-4-19
Open

tonyxrmdavidson wants to merge 1 commit into
openshift:release-4.19from
tonyxrmdavidson:OCPBUGS-103732-CVE-2026-33814-4-19

Conversation

@tonyxrmdavidson

Copy link
Copy Markdown

Fixes CVE-2026-33814 (GO-2026-4918): a malicious or compromised HTTP/2 server can send a SETTINGS_MAX_FRAME_SIZE value of 0, which causes golang.org/x/net/http2's client transport to loop indefinitely writing CONTINUATION frames — a client-side denial-of-service.

node_exporter pulls golang.org/x/net in transitively (node_exporter → prometheus/exporter-toolkit/web → prometheus/common/config → golang.org/x/net/http2), and govulncheck confirms a reachable call path through the (opt-in, documented) supervisord collector:

collector.supervisordCollector.Update → xmlrpc.Client.Call → http2.Transport.RoundTrip

The supervisord collector is defaultDisabled and only exercises this path if an operator enables --collector.supervisord and points --collector.supervisord.url/SUPERVISORD_URL at an https:// (or h2c) endpoint an attacker controls or can MITM — but it is a standard, documented, non-hidden flag, so this is treated as a real fix rather than a low-priority housekeeping bump.

Fix
Vendored golang.org/x/net was below the fixed version (v0.37.0 on this branch; fix lands in v0.53.0). Rather than a direct go get bump — which would have dragged the go directive and several unrelated transitive deps (x/crypto, x/sync, x/sys, x/text) along with it — this uses the OpenShift sustaining fork via a replace directive to apply only the security fix:

replace golang.org/x/net => github.com/openshift-sustaining/net v0.43.0-sec.4

This keeps the diff minimal and avoids an unplanned go version bump on a stable release branch.

Root cause verified in vendor
vendor/golang.org/x/net/http2/http2.go:139 (Setting.Valid()) now rejects SettingMaxFrameSize values outside the valid RFC 7540 range [16384, 2^24-1] — which includes the malicious 0 — returning ConnectionError(ErrCodeProtocol) instead of allowing the transport to spin.

Test plan
[x] go mod verify — all modules verified
[x] go build -mod=vendor ./... — builds clean
[x] go vet ./... — clean
[x] make test — all packages pass (fixtures extracted via ttar; go test ./... alone will fail with an unrelated fixture-extraction panic in TestAccelerator if run without make test first)
[x] govulncheck ./... — GO-2026-4918 no longer reported (previously flagged via the supervisord collector call chain above)
[x] Manual inspection of vendored fix confirms the upstream SettingMaxFrameSize range check is present
References
CVE-2026-33814 / GO-2026-4918: https://pkg.go.dev/vuln/GO-2026-4918
Fixed in golang.org/x/net@v0.53.0
OCPBUGS-103732

…r-rhel9: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [openshift-4.19]
@openshift-merge-bot

Copy link
Copy Markdown

Pipeline controller notification

This PR uses the pipeline controller for second-stage tests. Selection and triggering follow the repository configuration.

Use /test ? to list jobs, /pipeline remaining to request missing second-stage tests, or /pipeline required to rerun the selected second-stage set.

@openshift-ci-robot openshift-ci-robot added jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. labels Oct 2, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@tonyxrmdavidson: This pull request references Jira Issue OCPBUGS-103732, which is invalid:

  • expected dependent Jira Issue OCPBUGS-103944 to be in one of the following states: VERIFIED, RELEASE PENDING, CLOSED (ERRATA), CLOSED (CURRENT RELEASE), CLOSED (DONE), CLOSED (DONE-ERRATA), but it is ASSIGNED instead

Comment /jira refresh to re-evaluate validity if changes to the Jira bug are made, or edit the title of this pull request to link to a different bug.

The bug has been updated to refer to the pull request using the external bug tracker.

Details

In response to this:

Fixes CVE-2026-33814 (GO-2026-4918): a malicious or compromised HTTP/2 server can send a SETTINGS_MAX_FRAME_SIZE value of 0, which causes golang.org/x/net/http2's client transport to loop indefinitely writing CONTINUATION frames — a client-side denial-of-service.

node_exporter pulls golang.org/x/net in transitively (node_exporter → prometheus/exporter-toolkit/web → prometheus/common/config → golang.org/x/net/http2), and govulncheck confirms a reachable call path through the (opt-in, documented) supervisord collector:

collector.supervisordCollector.Update → xmlrpc.Client.Call → http2.Transport.RoundTrip

The supervisord collector is defaultDisabled and only exercises this path if an operator enables --collector.supervisord and points --collector.supervisord.url/SUPERVISORD_URL at an https:// (or h2c) endpoint an attacker controls or can MITM — but it is a standard, documented, non-hidden flag, so this is treated as a real fix rather than a low-priority housekeeping bump.

Fix
Vendored golang.org/x/net was below the fixed version (v0.37.0 on this branch; fix lands in v0.53.0). Rather than a direct go get bump — which would have dragged the go directive and several unrelated transitive deps (x/crypto, x/sync, x/sys, x/text) along with it — this uses the OpenShift sustaining fork via a replace directive to apply only the security fix:

replace golang.org/x/net => github.com/openshift-sustaining/net v0.43.0-sec.4

This keeps the diff minimal and avoids an unplanned go version bump on a stable release branch.

Root cause verified in vendor
vendor/golang.org/x/net/http2/http2.go:139 (Setting.Valid()) now rejects SettingMaxFrameSize values outside the valid RFC 7540 range [16384, 2^24-1] — which includes the malicious 0 — returning ConnectionError(ErrCodeProtocol) instead of allowing the transport to spin.

Test plan
[x] go mod verify — all modules verified
[x] go build -mod=vendor ./... — builds clean
[x] go vet ./... — clean
[x] make test — all packages pass (fixtures extracted via ttar; go test ./... alone will fail with an unrelated fixture-extraction panic in TestAccelerator if run without make test first)
[x] govulncheck ./... — GO-2026-4918 no longer reported (previously flagged via the supervisord collector call chain above)
[x] Manual inspection of vendored fix confirms the upstream SettingMaxFrameSize range check is present
References
CVE-2026-33814 / GO-2026-4918: https://pkg.go.dev/vuln/GO-2026-4918
Fixed in golang.org/x/net@v0.53.0
OCPBUGS-103732

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci
openshift-ci Bot requested review from marioferh and slashpai October 2, 2026 11:22
@tonyxrmdavidson

Copy link
Copy Markdown
Author

/pipeline required

@openshift-merge-bot

Copy link
Copy Markdown

Scheduling required tests:
/test e2e-agnostic-cmo
/test e2e-aws
/test e2e-aws-upgrade

@simonpasquier

Copy link
Copy Markdown

/approve
/lgtm
/label backport-risk-assessed
/verified by @simonpasquier

@openshift-ci-robot openshift-ci-robot added the verified Signifies that the PR passed pre-merge verification criteria label Oct 2, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@simonpasquier: This PR has been marked as verified by @simonpasquier.

Details

In response to this:

/approve
/lgtm
/label backport-risk-assessed
/verified by @simonpasquier

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@openshift-ci openshift-ci Bot added the backport-risk-assessed Indicates a PR to a release branch has been evaluated and considered safe to accept. label Oct 2, 2026
@openshift-ci openshift-ci Bot added the lgtm Indicates that a PR is ready to be merged. label Oct 2, 2026
@openshift-ci

openshift-ci Bot commented Oct 2, 2026

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: simonpasquier, tonyxrmdavidson

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci openshift-ci Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 2, 2026
@openshift-ci

openshift-ci Bot commented Oct 2, 2026

Copy link
Copy Markdown

@tonyxrmdavidson: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. backport-risk-assessed Indicates a PR to a release branch has been evaluated and considered safe to accept. jira/invalid-bug Indicates that a referenced Jira bug is invalid for the branch this PR is targeting. jira/severity-important Referenced Jira bug's severity is important for the branch this PR is targeting. jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. lgtm Indicates that a PR is ready to be merged. verified Signifies that the PR passed pre-merge verification criteria

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants