CVE-2019-9515
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 87.4%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 87.40% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400, CWE-770
- Affected
- apple/swiftnio · apache/traffic server · canonical/ubuntu linux · debian/debian linux · synology/skynas · synology/diskstation manager · synology/vs960hd firmware · fedoraproject/fedora · opensuse/leap · redhat/jboss core services · redhat/jboss enterprise application platform · redhat/openshift container platform · redhat/openshift service mesh · redhat/openstack · redhat/quay · redhat/single sign-on · redhat/software collections · redhat/enterprise linux · oracle/graalvm · mcafee/web gateway · +2 more
- Source
- cret@cert.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlMailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2019/Aug/16Mailing List, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2766Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2796Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2861Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2925Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2939Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2955Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3892Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4018Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4019Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4020Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4021Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4040Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4041Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4042Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4045Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:4352Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0727Third Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.mdThird Party Advisory
- https://kb.cert.org/vuls/id/605641/Third Party Advisory, US Government Resource
- https://kc.mcafee.com/corporate/index?page=content&id=SB10296Third Party Advisory
- https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3E
- https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3E
- https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/
- https://seclists.org/bugtraq/2019/Aug/24Mailing List, Third Party Advisory
- https://seclists.org/bugtraq/2019/Aug/43Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.