Vulnerability CVE-2019-9513: Information

Description

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 14, 2019
Modified: Nov. 7, 2023

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
libnghttp2sisyphus1.39.2-alt11.61.0-alt1ALT-PU-2019-2601-1236978Fixed
libnghttp2p101.39.2-alt11.61.0-alt1ALT-PU-2019-2601-1236978Fixed
libnghttp2p91.40.0-alt11.41.0-alt1ALT-PU-2020-2194-1247371Fixed
libnghttp2c10f11.39.2-alt11.61.0-alt1ALT-PU-2019-2601-1236978Fixed
libnghttp2c9f21.40.0-alt11.61.0-alt1ALT-PU-2020-2194-1247371Fixed
nginxsisyphus1.16.1-alt11.24.0-alt6ALT-PU-2019-2600-1236982Fixed
nginxp101.16.1-alt11.24.0-alt6ALT-PU-2019-2600-1236982Fixed
nginxp91.16.1-alt11.24.0-alt3ALT-PU-2019-2823-1238637Fixed
nginxp81.16.1-alt11.24.0-alt3ALT-PU-2019-2932-1236984Fixed
nginxc10f11.16.1-alt11.24.0-alt5ALT-PU-2019-2600-1236982Fixed
nginxc9f21.16.1-alt11.24.0-alt5ALT-PU-2019-2823-1238637Fixed
nodesisyphus10.17.0-alt120.12.1-alt1ALT-PU-2019-3050-1239770Fixed
nodep1010.17.0-alt116.19.1-alt1ALT-PU-2019-3050-1239770Fixed
nodep914.3.0-alt114.17.2-alt1ALT-PU-2020-2195-1247371Fixed
nodec10f110.17.0-alt116.19.1-alt1ALT-PU-2019-3050-1239770Fixed
nodec9f214.3.0-alt116.19.1-alt0.c9.1ALT-PU-2020-2195-1247371Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
VU#605641
  • Third Party Advisory
  • US Government Resource
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
  • Third Party Advisory
USN-4099-1
  • Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_33
  • Third Party Advisory
https://support.f5.com/csp/article/K02591030
  • Third Party Advisory
20190822 [SECURITY] [DSA 4505-1] nginx security update
  • Mailing List
  • Third Party Advisory
DSA-4505
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0005/
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0002/
  • Third Party Advisory
20190902 [SECURITY] [DSA 4511-1] nghttp2 security update
  • Mailing List
  • Third Party Advisory
DSA-4511
  • Third Party Advisory
RHSA-2019:2692
  • Third Party Advisory
openSUSE-SU-2019:2120
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2114
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2115
  • Mailing List
  • Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10296
  • Third Party Advisory
RHSA-2019:2746
  • Third Party Advisory
RHSA-2019:2745
  • Third Party Advisory
RHSA-2019:2775
  • Third Party Advisory
RHSA-2019:2799
  • Third Party Advisory
RHSA-2019:2925
  • Third Party Advisory
RHSA-2019:2939
  • Third Party Advisory
RHSA-2019:2949
  • Third Party Advisory
openSUSE-SU-2019:2232
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2234
  • Mailing List
  • Third Party Advisory
RHSA-2019:2955
  • Third Party Advisory
RHSA-2019:2966
  • Third Party Advisory
openSUSE-SU-2019:2264
  • Mailing List
  • Third Party Advisory
RHSA-2019:3041
  • Third Party Advisory
RHSA-2019:3935
  • Third Party Advisory
RHSA-2019:3933
  • Third Party Advisory
RHSA-2019:3932
  • Third Party Advisory
DSA-4669
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html
  • Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html
  • Third Party Advisory
FEDORA-2019-befd924cfe
    FEDORA-2019-81985a8858
      FEDORA-2019-5a6a7bc12c
        FEDORA-2019-6a2980de56
          FEDORA-2019-8a437d5c2f
            FEDORA-2019-7a0b45fdc4
              https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS
                  1. Configuration 1

                    cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:*

                    Running on/with:
                    cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

                    Running on/with:
                    cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*

                    Configuration 2

                    cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                    Start including
                    8.0.0
                    End including
                    8.0.3

                    cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                    Start including
                    7.0.0
                    End including
                    7.1.6

                    cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                    Start including
                    6.0.0
                    End including
                    6.2.3

                    Configuration 3

                    cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

                    cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

                    cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

                    Configuration 4

                    cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

                    cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                    Configuration 5

                    cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*

                    cpe:2.3:a:synology:diskstation_manager:6.2:*:*:*:*:*:*:*

                    Configuration 6

                    cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*

                    Running on/with:
                    cpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*

                    Configuration 7

                    cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                    cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

                    Configuration 8

                    cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

                    cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                    Configuration 9

                    cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

                    cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

                    Configuration 10

                    cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*

                    cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*

                    cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

                    cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*

                    cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

                    cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:*

                    cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*

                    Configuration 11

                    cpe:2.3:a:oracle:graalvm:19.2.0:*:*:*:enterprise:*:*:*

                    Configuration 12

                    cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                    Start including
                    7.7.2.0
                    End excliding
                    7.7.2.24

                    cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                    Start including
                    7.8.2.0
                    End excliding
                    7.8.2.13

                    cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                    Start including
                    8.1.0
                    End excliding
                    8.2.0

                    Configuration 13

                    cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
                    Start including
                    1.9.5
                    End excliding
                    1.16.1

                    cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:*
                    Start including
                    1.17.0
                    End including
                    1.17.2

                    Configuration 14

                    cpe:2.3:a:oracle:enterprise_communications_broker:3.1.0:*:*:*:*:*:*:*

                    cpe:2.3:a:oracle:enterprise_communications_broker:3.2.0:*:*:*:*:*:*:*

                    Configuration 15

                    cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                    Start including
                    8.0.0
                    End including
                    8.8.1

                    cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                    Start including
                    10.0.0
                    End including
                    10.12.0

                    cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                    Start including
                    12.0.0
                    End excliding
                    12.8.1

                    cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
                    Start including
                    10.13.0
                    End excliding
                    10.16.3

                    cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
                    Start including
                    8.9.0
                    End excliding
                    8.16.1