Vulnerability CVE-2019-9517: Information

Description

Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.

Severity: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Published: Aug. 14, 2019
Modified: Nov. 7, 2023
Error type identifier: CWE-770

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
VU#605641
  • Third Party Advisory
  • US Government Resource
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
  • Third Party Advisory
[oss-security] 20190814 CVE-2019-9517: mod_http2, DoS attack by exhausting h2 workers
  • Mailing List
  • Third Party Advisory
https://www.synology.com/security/advisory/Synology_SA_19_33
  • Third Party Advisory
https://support.f5.com/csp/article/K02591030
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0005/
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190823-0003/
  • Third Party Advisory
DSA-4509
  • Third Party Advisory
20190826 [SECURITY] [DSA 4509-1] apache2 security update
  • Mailing List
  • Third Party Advisory
USN-4113-1
  • Third Party Advisory
openSUSE-SU-2019:2051
  • Mailing List
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190905-0003/
  • Third Party Advisory
GLSA-201909-04
  • Third Party Advisory
openSUSE-SU-2019:2114
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:2115
  • Mailing List
  • Third Party Advisory
https://kc.mcafee.com/corporate/index?page=content&id=SB10296
  • Third Party Advisory
RHSA-2019:2893
  • Third Party Advisory
RHSA-2019:2925
  • Third Party Advisory
RHSA-2019:2939
  • Third Party Advisory
RHSA-2019:2946
  • Third Party Advisory
RHSA-2019:2950
  • Third Party Advisory
RHSA-2019:2949
  • Third Party Advisory
RHSA-2019:2955
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
  • Patch
  • Third Party Advisory
RHSA-2019:3935
  • Third Party Advisory
RHSA-2019:3933
  • Third Party Advisory
RHSA-2019:3932
  • Third Party Advisory
N/A
  • Third Party Advisory
[httpd-announce] 20190814 CVE-2019-9517: mod_http2, DoS attack by exhausting h2 workers
    [httpd-cvs] 20190815 svn commit: r1048743 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
      [httpd-dev] 20190817 CVE-2019-10097 vs. CHANGEs entry
        [httpd-dev] 20190817 Re: CVE-2019-10097 vs. CHANGEs entry
          FEDORA-2019-5a6a7bc12c
            FEDORA-2019-6a2980de56
              FEDORA-2019-4427fd65be
                FEDORA-2019-63ba15cc83
                  https://support.f5.com/csp/article/K02591030?utm_source=f5support&amp%3Butm_medium=RSS
                    [httpd-cvs] 20200401 svn commit: r1058586 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
                      [httpd-cvs] 20200401 svn commit: r1058587 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/vulnerabilities-httpd.xml security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
                        [httpd-cvs] 20210330 svn commit: r1073139 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/json/
                          [httpd-cvs] 20210330 svn commit: r1073143 [3/3] - in /websites/staging/httpd/trunk/content: ./ security/
                            [httpd-cvs] 20210330 svn commit: r1073140 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/cvejsontohtml.py security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
                              [httpd-cvs] 20210330 svn commit: r1073139 [12/13] - in /websites/staging/httpd/trunk/content: ./ security/json/
                                [httpd-cvs] 20210330 svn commit: r1888194 [12/13] - /httpd/site/trunk/content/security/json/
                                  [httpd-cvs] 20210330 svn commit: r1073149 [1/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/
                                    [httpd-cvs] 20210330 svn commit: r1073149 [13/13] - in /websites/staging/httpd/trunk/content: ./ security/ security/json/
                                      [httpd-cvs] 20210606 svn commit: r1075470 [4/4] - in /websites/staging/httpd/trunk/content: ./ security/json/CVE-2020-13938.json security/vulnerabilities_13.html security/vulnerabilities_20.html security/vulnerabilities_22.html security/vulnerabilities_24.html
                                          1. Configuration 1

                                            cpe:2.3:a:apple:swiftnio:*:*:*:*:*:*:*:*

                                            Running on/with:
                                            cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

                                            Running on/with:
                                            cpe:2.3:o:canonical:ubuntu_linux:*:*:*:*:*:*:*:*

                                            Configuration 2

                                            cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                                            Start including
                                            8.0.0
                                            End including
                                            8.0.3

                                            cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                                            Start including
                                            7.0.0
                                            End including
                                            7.1.6

                                            cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*
                                            Start including
                                            6.0.0
                                            End including
                                            6.2.3

                                            cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
                                            Start including
                                            2.4.20
                                            End excliding
                                            2.4.40

                                            Configuration 3

                                            cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

                                            cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

                                            cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

                                            Configuration 4

                                            cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                                            cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

                                            Configuration 5

                                            cpe:2.3:a:synology:skynas:-:*:*:*:*:*:*:*

                                            cpe:2.3:a:synology:diskstation_manager:6.2:*:*:*:*:*:*:*

                                            Configuration 6

                                            cpe:2.3:o:synology:vs960hd_firmware:-:*:*:*:*:*:*:*

                                            Running on/with:
                                            cpe:2.3:h:synology:vs960hd:-:*:*:*:*:*:*:*

                                            Configuration 7

                                            cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*

                                            cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                                            Configuration 8

                                            cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

                                            cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

                                            Configuration 9

                                            cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:redhat:jboss_core_services:1.0:*:*:*:*:*:*:*

                                            cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:redhat:quay:3.0.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:redhat:openshift_service_mesh:1.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3.0:*:*:*:*:*:*:*

                                            Configuration 10

                                            cpe:2.3:a:oracle:retail_xstore_point_of_service:7.1:*:*:*:*:*:*:*

                                            cpe:2.3:a:oracle:graalvm:19.2.0:*:*:*:enterprise:*:*:*

                                            cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:*
                                            Start including
                                            17.1
                                            End including
                                            17.3

                                            cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*

                                            cpe:2.3:a:oracle:communications_element_manager:8.1.0:*:*:*:*:*:*:*

                                            cpe:2.3:a:oracle:communications_element_manager:8.0.0:*:*:*:*:*:*:*

                                            Configuration 11

                                            cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                                            Start including
                                            7.7.2.0
                                            End excliding
                                            7.7.2.24

                                            cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                                            Start including
                                            7.8.2.0
                                            End excliding
                                            7.8.2.13

                                            cpe:2.3:a:mcafee:web_gateway:*:*:*:*:*:*:*:*
                                            Start including
                                            8.1.0
                                            End excliding
                                            8.2.0

                                            Configuration 12

                                            cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*

                                            Configuration 13

                                            cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                                            Start including
                                            8.0.0
                                            End including
                                            8.8.1

                                            cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                                            Start including
                                            10.0.0
                                            End including
                                            10.12.0

                                            cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:*
                                            Start including
                                            12.0.0
                                            End excliding
                                            12.8.1

                                            cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
                                            Start including
                                            10.13.0
                                            End excliding
                                            10.16.3

                                            cpe:2.3:a:nodejs:node.js:*:*:*:*:lts:*:*:*
                                            Start including
                                            8.9.0
                                            End excliding
                                            8.16.1