SB2023101124 - Rapid Reset attack in h2o
Published: October 11, 2023 Updated: December 6, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2023-44487)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improperly control of consumption for internal resources when handling HTTP/2 requests with compressed HEADERS frames. A remote attacker can send a sequence of compressed HEADERS frames followed by RST_STREAM frames and perform a denial of service (DoS) attack, a.k.a. "Rapid Reset".
Note, the vulnerability is being actively exploited in the wild.
Remediation
Install update from vendor's website.
References
- https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf"
- https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf</a></p><p><a
- https://github.com/h2o/h2o/commit/28fe15117b909588bf14269a0e1c6ec4548579fe"
- https://github.com/h2o/h2o/commit/28fe15117b909588bf14269a0e1c6ec4548579fe</a></p><p>
- https://github.com/h2o/h2o/pull/3291<br></p>