Resource exhaustion in NGINX Open Source - CVE-2019-9511
Published: August 13, 2019 / Updated: August 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing HTTP/2 requests. A remote attacker can send a specially crafted HTTP/2 request the affected server, consume all available CPU resources and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that support for HTTP/2 is enabled.
Affected software
Arch Linux
Amazon Linux AMI
SUSE OpenStack Cloud
Fedora
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
HPE Helion Openstack
Microsoft Windows
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
Opensuse
Ubuntu
Windows Server
JBoss Core Services
AMQ Broker
JBoss Enterprise Application Platform
Red Hat Software Collections
nginx (Alpine package)
nginx (Ubuntu package)
nginx (Debian package)
nghttp2 (Debian package)
nghttp2 (Alpine package)
nodejs (Debian package)
nodejs (Alpine package)
nghttp2-server (Ubuntu package)
nghttp2-proxy (Ubuntu package)
nghttp2-client (Ubuntu package)
nghttp2 (Ubuntu package)
libnghttp2-14 (Ubuntu package)
nginx
mod_http2
nghttp2
libnghttp2-14-debuginfo
nghttp2-debugsource
nghttp2-debuginfo
libnghttp2-14-debuginfo-32bit
libnghttp2-14-32bit
libnghttp2-14
nodejs
IBM Cloud Transformation Advisor
IBM Process Mining
IBM Spectrum Protect Storage Agent
Quay
Oracle GraalVM Enterprise Edition
HPE Moonshot 1500 Chassis Manager
How to mitigate CVE-2019-9511
nginx (Alpine package) - addressed in versions 1.14.2-r1, 1.14.2-r2
nginx (Ubuntu package) - addressed in versions 1.10.3-0ubuntu0.16.04.4, 1.14.0-0ubuntu1.4, 1.15.9-0ubuntu1.1
nginx (Debian package) - update to 1.10.3-1+deb9u3
nghttp2 (Debian package) - addressed in versions 1.18.1-1+deb9u1, 1.36.0-2+deb10u1
nghttp2 (Alpine package) - addressed in versions 1.35.1-r1, 1.39.2-r0
Quay - update to 3.1.1
AMQ Broker - addressed in versions 7.4.3, 7.6
JBoss Enterprise Application Platform - update to 7.2.5
nodejs (Debian package) - update to 10.19.0~dfsg1-1
nodejs (Alpine package) - update to 10.16.3-r0
nghttp2-server (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nghttp2-proxy (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nghttp2-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nghttp2 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
libnghttp2-14 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.40.0-1ubuntu0.3, 1.43.0-1ubuntu0.2, 1.55.1-1ubuntu0.2, 1.59.0-1ubuntu0.1
nginx - addressed in versions mainline-2920190816153353.6c81f848, mainline-3020190816153353.a5b0195c, 1.16.1-1.fc29, 1.16.1-1.fc30
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
nghttp2 - addressed in versions 1.31.1-2.el7, 1.39.2-1.fc29, 1.39.2-1.fc30
libnghttp2-14-debuginfo - update to 1.39.2-3.5.1
nghttp2-debugsource - update to 1.39.2-3.5.1
nghttp2-debuginfo - update to 1.39.2-3.5.1
libnghttp2-14-debuginfo-32bit - update to 1.39.2-3.5.1
libnghttp2-14-32bit - update to 1.39.2-3.5.1
libnghttp2-14 - update to 1.39.2-3.5.1
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 12-2920190821145457.6c81f848, 12-3020190821145457.a5b0195c
External References
Related Security Bulletins
- Remote denial of service in nginx
- Remote denial of service in HTTP/2 implementation in Microsoft Windows
- Ubuntu update for nginx
- Arch Linux update for nginx-mainline
- Arch Linux update for nginx
- Arch Linux update for libnghttp2
- Debian update for nginx
- Debian update for nghttp2
- Red Hat update for nghttp2
- OpenSUSE Linux update for nginx
- OpenSUSE Linux update for nodejs10
- OpenSUSE Linux update for nodejs8
- Red Hat update for rh-nginx110-nginx
- Red Hat update for rh-nginx114-nginx
- Red Hat update for nginx:1.14
- Red Hat update for rh-nginx112-nginx
- Red Hat update for nodejs:10
- OpenSUSE Linux update for nghttp2
- Red Hat update for rh-nodejs10-nodejs
- Red Hat update for httpd24-httpd and httpd24-nghttp2
- OpenSUSE Linux update for nghttp2
- Red Hat update for rh-nodejs8-nodejs
- Amazon Linux AMI update for nghttp2
- Amazon Linux AMI update for nginx
- Red Hat update for Red Hat Quay v3.1.1
- OpenSUSE Linux update for nginx
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 6)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 7)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 8)
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Multiple vulnerabilities in Red Hat AMQ Broker
- Debian update for nodejs
- Multiple vulnerabilities in Oracle GraalVM Enterprise Edition
- Resource exhaustion in nghttp2 (Alpine package)
- Resource exhaustion in nodejs (Alpine package)
- Resource exhaustion in nginx (Alpine package)
- Multiple vulnerabilities in IBM Process Mining
- SUSE update for nghttp2
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Protect Server
- Ubuntu update for nghttp2
- Ubuntu update for nghttp2
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 30 update for nginx
- Fedora 30 update for nghttp2
- Fedora 29 Modular update for nginx
- Fedora 30 Modular update for nginx
- Fedora 29 update for mod_http2
- Fedora 29 update for nghttp2
- Fedora EPEL 7 update for nghttp2
- Fedora 30 update for mod_http2
- Fedora 29 Modular update for nodejs
- Fedora 30 Modular update for nodejs
- Fedora 29 update for nginx