OCPBUGS-103732: CVE-2026-33814 openshift4/ose-prometheus-node-exporter-rhel9: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [openshift-4.19] - #215
Conversation
…r-rhel9: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame [openshift-4.19]
|
Pipeline controller notification This PR uses the pipeline controller for second-stage tests. Selection and triggering follow the repository configuration. Use |
|
@tonyxrmdavidson: This pull request references Jira Issue OCPBUGS-103732, which is invalid:
Comment The bug has been updated to refer to the pull request using the external bug tracker. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
/pipeline required |
|
Scheduling required tests: |
|
/approve |
|
@simonpasquier: This PR has been marked as verified by DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository. |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: simonpasquier, tonyxrmdavidson The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
@tonyxrmdavidson: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Fixes CVE-2026-33814 (GO-2026-4918): a malicious or compromised HTTP/2 server can send a SETTINGS_MAX_FRAME_SIZE value of 0, which causes golang.org/x/net/http2's client transport to loop indefinitely writing CONTINUATION frames — a client-side denial-of-service.
node_exporter pulls golang.org/x/net in transitively (node_exporter → prometheus/exporter-toolkit/web → prometheus/common/config → golang.org/x/net/http2), and govulncheck confirms a reachable call path through the (opt-in, documented) supervisord collector:
collector.supervisordCollector.Update → xmlrpc.Client.Call → http2.Transport.RoundTrip
The supervisord collector is defaultDisabled and only exercises this path if an operator enables --collector.supervisord and points --collector.supervisord.url/SUPERVISORD_URL at an https:// (or h2c) endpoint an attacker controls or can MITM — but it is a standard, documented, non-hidden flag, so this is treated as a real fix rather than a low-priority housekeeping bump.
Fix
Vendored golang.org/x/net was below the fixed version (v0.37.0 on this branch; fix lands in v0.53.0). Rather than a direct go get bump — which would have dragged the go directive and several unrelated transitive deps (x/crypto, x/sync, x/sys, x/text) along with it — this uses the OpenShift sustaining fork via a replace directive to apply only the security fix:
replace golang.org/x/net => github.com/openshift-sustaining/net v0.43.0-sec.4
This keeps the diff minimal and avoids an unplanned go version bump on a stable release branch.
Root cause verified in vendor
vendor/golang.org/x/net/http2/http2.go:139 (Setting.Valid()) now rejects SettingMaxFrameSize values outside the valid RFC 7540 range [16384, 2^24-1] — which includes the malicious 0 — returning ConnectionError(ErrCodeProtocol) instead of allowing the transport to spin.
Test plan
[x] go mod verify — all modules verified
[x] go build -mod=vendor ./... — builds clean
[x] go vet ./... — clean
[x] make test — all packages pass (fixtures extracted via ttar; go test ./... alone will fail with an unrelated fixture-extraction panic in TestAccelerator if run without make test first)
[x] govulncheck ./... — GO-2026-4918 no longer reported (previously flagged via the supervisord collector call chain above)
[x] Manual inspection of vendored fix confirms the upstream SettingMaxFrameSize range check is present
References
CVE-2026-33814 / GO-2026-4918: https://pkg.go.dev/vuln/GO-2026-4918
Fixed in golang.org/x/net@v0.53.0
OCPBUGS-103732