mirror of
https://github.com/debauchee/barrier.git
synced 2026-05-05 11:21:29 +08:00
lib/server: Close connection when client app-level handshake fails
This fixes the following security vulnerability: - CVE-2021-42075 DoS via file descriptor exhaustion The issue has been reported by Matthias Gerstner <mgerstner@suse.de>.
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
SECURITY ISSUE
|
||||
|
||||
Barrier will now correctly close connections when the app-level handshake fails (fixes CVE-2021-42075).
|
||||
|
||||
Previously repeated failing connections would leak file descriptors leading to Barrier being unable
|
||||
to receive new connections from clients.
|
||||
Reference in New Issue
Block a user