Resource exhaustion in NGINX Open Source - CVE-2019-9516

 

Resource exhaustion in NGINX Open Source - CVE-2019-9516

Published: August 13, 2019 / Updated: August 13, 2019


Vulnerability identifier: #VU20198
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9516
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation when processing HTTP/2 requests within the ngx_http_v2_module module. A remote attacker can send a specially crafted HTTP/2 request the affected server, consume all available CPU resources and perform a denial of service (DoS) attack.

Successful exploitation of the vulnerability requires that support for HTTP/2 is enabled.


Affected software

NGINX Open Source
JBoss Core Services
AMQ Broker
Fuse
Amazon Linux AMI
Arch Linux
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
Red Hat Software Collections
nginx (Alpine package)
nginx (Ubuntu package)
nginx (Debian package)
nodejs (Alpine package)
nginx
mod_http2
nodejs
IBM Cloud Transformation Advisor
IBM Process Mining
IBM Spectrum Protect Storage Agent
Quay

How to mitigate CVE-2019-9516

Install updates from vendor's website.

NGINX Open Source - addressed in versions 1.16.1, 1.17.3
nginx (Alpine package) - addressed in versions 1.14.2-r1, 1.14.2-r2
nginx (Ubuntu package) - addressed in versions 1.10.3-0ubuntu0.16.04.4, 1.14.0-0ubuntu1.4, 1.15.9-0ubuntu1.1
nginx (Debian package) - update to 1.10.3-1+deb9u3
Quay - update to 3.1.1
AMQ Broker - addressed in versions 7.4.3, 7.6
Fuse - update to 7.6.0
nodejs (Alpine package) - update to 10.16.3-r0
nginx - addressed in versions mainline-2920190816153353.6c81f848, mainline-3020190816153353.a5b0195c, 1.16.1-1.fc29, 1.16.1-1.fc30
IBM Process Mining - update to 1.12.0.4
mod_http2 - addressed in versions 1.15.3-2.fc29, 1.15.3-2.fc30
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c, 12.20.1-1.fc32, 12-3220210105181808.43bbeeef, 12-3320210105181808.601d93de

External References

Related Security Bulletins