ISOMAN

CVE

CVE-2019-9514

Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.html
  3. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.html
  4. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.html
  5. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.html
  6. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.html
  7. http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.html
  8. http://seclists.org/fulldisclosure/2019/Aug/16
  9. http://www.openwall.com/lists/oss-security/2019/08/20/1
  10. http://www.openwall.com/lists/oss-security/2023/10/18/8
  11. https://access.redhat.com/errata/RHSA-2019:2594
  12. https://access.redhat.com/errata/RHSA-2019:2661
  13. https://access.redhat.com/errata/RHSA-2019:2682
  14. https://access.redhat.com/errata/RHSA-2019:2690
  15. https://access.redhat.com/errata/RHSA-2019:2726
  16. https://access.redhat.com/errata/RHSA-2019:2766
  17. https://access.redhat.com/errata/RHSA-2019:2769
  18. https://access.redhat.com/errata/RHSA-2019:2796
  19. https://access.redhat.com/errata/RHSA-2019:2861
  20. https://access.redhat.com/errata/RHSA-2019:2925