Resource exhaustion in NGINX Open Source - CVE-2019-9516
Published: August 13, 2019 / Updated: August 13, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing HTTP/2 requests within the ngx_http_v2_module module. A remote attacker can send a specially crafted HTTP/2 request the affected server, consume all available CPU resources and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that support for HTTP/2 is enabled.
Affected software
JBoss Core Services
AMQ Broker
Fuse
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Red Hat Software Collections
nginx (Alpine package)
nginx (Ubuntu package)
nginx (Debian package)
nodejs (Alpine package)
nginx
mod_http2
nodejs
IBM Cloud Transformation Advisor
IBM Process Mining
IBM Spectrum Protect Storage Agent
Quay
How to mitigate CVE-2019-9516
nginx (Alpine package) - addressed in versions 1.14.2-r1, 1.14.2-r2
nginx (Ubuntu package) - addressed in versions 1.10.3-0ubuntu0.16.04.4, 1.14.0-0ubuntu1.4, 1.15.9-0ubuntu1.1
nginx (Debian package) - update to 1.10.3-1+deb9u3
Quay - update to 3.1.1
AMQ Broker - addressed in versions 7.4.3, 7.6
Fuse - update to 7.6.0
nodejs (Alpine package) - update to 10.16.3-r0
nginx - addressed in versions mainline-2920190816153353.6c81f848, mainline-3020190816153353.a5b0195c, 1.16.1-1.fc29, 1.16.1-1.fc30
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c, 12.20.1-1.fc32, 12-3220210105181808.43bbeeef, 12-3320210105181808.601d93de
External References
Related Security Bulletins
- Remote denial of service in nginx
- Ubuntu update for nginx
- Arch Linux update for nginx-mainline
- Arch Linux update for nginx
- Debian update for nginx
- OpenSUSE Linux update for nginx
- OpenSUSE Linux update for nodejs10
- OpenSUSE Linux update for nodejs8
- Red Hat update for rh-nginx110-nginx
- Red Hat update for rh-nginx114-nginx
- Red Hat update for nginx:1.14
- Red Hat update for rh-nginx112-nginx
- Red Hat update for nodejs:10
- Red Hat update for rh-nodejs10-nodejs
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP3
- Red Hat update for Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP3
- Red Hat update for rh-nodejs8-nodejs
- Amazon Linux AMI update for nginx
- Red Hat update for Red Hat Quay v3.1.1
- OpenSUSE Linux update for nginx
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37
- Red Hat JBoss Core Services update for Apache HTTP Server 2.4.37 (RHEL 6)
- Red Hat JBoss Core Services update Apache HTTP Server 2.4.37 (RHEL 7)
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat AMQ Broker
- Resource exhaustion in nodejs (Alpine package)
- Resource exhaustion in nginx (Alpine package)
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Protect Server
- Fedora 32 Modular update for nodejs
- Fedora 33 Modular update for nodejs
- Fedora 32 update for nodejs
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 30 update for nginx
- Fedora 29 Modular update for nginx
- Fedora 30 Modular update for nginx
- Fedora 30 Modular update for nodejs
- Fedora 29 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 update for nodejs
- Fedora 29 update for mod_http2
- Fedora 30 update for mod_http2
- Fedora 29 update for nginx