Resource management error in NGINX Open Source - CVE-2018-16844
Published: November 7, 2018
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to excessive CPU usage when processing HTTP/2 requests within the ngx_http_v2_module module. A remote attacker can send specially crafted HTTP/2 requests to the affected web server and cause high CPU usage and perform a denial of service (DoS) attack.
Affected software
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
nginx (Alpine package)
nginx
IBM Cloud Private
How to mitigate CVE-2018-16844
nginx (Alpine package) - update to 1.12.2-r2
IBM Cloud Private - addressed in versions 3.2.1.2203, 3.2.2.2203
nginx - addressed in versions 1.14.1-1.fc27, 1.14.1-1.fc28, 1.14.1-2.fc29
External References
Related Security Bulletins
- Multiple vulnerabilities in nginx
- Debian update for nginx
- Red Hat update for nginx
- Red Hat update for nginx
- Amazon Linux AMI update for nginx
- OpenSUSE Linux update for nginx
- OpenSUSE Linux update for nginx
- Resource management error in nginx (Alpine package)
- IBM Cloud Private update for nginx
- Fedora 29 update for nginx
- Fedora 28 update for nginx
- Fedora 27 update for nginx