Resource exhaustion in Microsoft Windows and Windows Server - CVE-2019-9512
Published: August 13, 2019 / Updated: August 14, 2025
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper validation of user-supplied input when processing HTTP/2 requests. A remote attacker can send specially crafted HTTP packets to the affected system trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Windows Server
Arch Linux
Amazon Linux AMI
Fedora
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Opensuse
IBM Observability with Instana
IBM PureData System for Operational Analytics
IBM Cloud Transformation Advisor
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Process Mining
IBM Spectrum Protect Storage Agent
k3s (Alpine package)
containerd (Alpine package)
ansible-service-broker (Red Hat package)
traefik (Alpine package)
golang-1.11 (Debian package)
go (Alpine package)
h2o (Debian package)
h2o (Alpine package)
openshift-ansible (Red Hat package)
openshift (Red Hat package)
atomic-enterprise-service-catalog (Red Hat package)
trafficserver (Debian package)
py3-twisted (Alpine package)
openshift-external-storage (Red Hat package)
openvswitch-ovn-kubernetes (Red Hat package)
openshift-eventrouter (Red Hat package)
skopeo (Red Hat package)
golang-github-openshift-prometheus-alert-buffer (Red Hat package)
golang-github-prometheus-promu (Red Hat package)
containernetworking-plugins (Red Hat package)
golang-github-prometheus-alertmanager (Red Hat package)
cri-tools (Red Hat package)
podman (Red Hat package)
hawkular-openshift-agent (Red Hat package)
heapster (Red Hat package)
cri-o (Red Hat package)
golang
golang-github-openshift-oauth-proxy (Red Hat package)
image-inspector (Red Hat package)
golang-github-prometheus-prometheus (Red Hat package)
openshift-enterprise-image-registry (Red Hat package)
atomic-openshift-node-problem-detector (Red Hat package)
atomic-openshift-descheduler (Red Hat package)
atomic-openshift (Red Hat package)
atomic-openshift-web-console (Red Hat package)
golang-github-prometheus-node_exporter (Red Hat package)
nodejs
cockpit (Red Hat package)
Red Hat Developer Tools
Red Hat Software Collections
Quay
Red Hat OpenShift Container Platform
IBM Cloud Pak for Watson AIOps
Dell DataIQ
Fuse
AMQ Broker
JBoss Enterprise Application Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat Single Sign-On
IBM Tivoli Application Dependency Discovery Manager
BIG-IP LTM
Twisted Web
How to mitigate CVE-2019-9512
containerd (Alpine package) - addressed in versions 1.2.9-r0, 1.3.3-r0
ansible-service-broker (Red Hat package) - addressed in versions 1.1.20-2.el7, 1.4.4-2.el7
traefik (Alpine package) - update to 2.0.4-r0
golang-1.11 (Debian package) - update to 1.11.6-1+deb10u1
go (Alpine package) - update to 1.12.8-r0
h2o (Debian package) - update to 2.2.5+dfsg2-2+deb10u1
h2o (Alpine package) - update to 2.2.6-r0
Quay - update to 3.1.1
openshift-ansible (Red Hat package) - update to 4.1.17-201909170941.git.162.79c271c.el7
Red Hat OpenShift Container Platform - addressed in versions 3.9, 3.11.154, 4.1.17, 4.1.20, 4.1.21, 4.2.1
openshift (Red Hat package) - addressed in versions 4.1.17-201909170941.git.0.2447974.el7, 4.1.17-201909170941.git.0.2447974.el8
atomic-enterprise-service-catalog (Red Hat package) - update to 4.1.17-201909170941.git.1.9b9b46b.el7
Fuse - addressed in versions 6.3.14, 7.5.0, 7.6.0
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
AMQ Broker - addressed in versions 7.4.3, 7.6
JBoss Enterprise Application Platform - update to 7.2.5
Red Hat Single Sign-On - update to 7.3.5
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u1
py3-twisted (Alpine package) - update to 20.3.0-r0
openshift-external-storage (Red Hat package) - update to 0.0.1-9.git78d6339.el7
openvswitch-ovn-kubernetes (Red Hat package) - update to 0.1.0-3.el7
openshift-eventrouter (Red Hat package) - update to 0.1-3.git5bd9251.el7
skopeo (Red Hat package) - update to 0.1.32-5.git1715c90.el8
golang-github-openshift-prometheus-alert-buffer (Red Hat package) - update to 0-3.gitceca8c1.el7
golang-github-prometheus-promu (Red Hat package) - update to 0-5.git85ceabc.el7
containernetworking-plugins (Red Hat package) - update to 0.5.2-6.el7
golang-github-prometheus-alertmanager (Red Hat package) - update to 0.14.0-2.git30af4d0.el7
cri-tools (Red Hat package) - update to 1.0.0-6.rhaos3.9.git8e6013a.el7
podman (Red Hat package) - update to 1.0.2-2.dev.git96ccc2e.el8
hawkular-openshift-agent (Red Hat package) - update to 1.2.2-3.el7
heapster (Red Hat package) - update to 1.3.0-4.el7
cri-o (Red Hat package) - update to 1.9.16-3.git858756d.el7
golang - addressed in versions 1.11.13-1.fc29, 1.12.9-1.fc30, 1.13-1.el6, 1.13-1.el7
IBM Process Mining - update to 1.12.0.4
Dell DataIQ - update to 2.1.1.0
golang-github-openshift-oauth-proxy (Red Hat package) - update to 2.1-3.git885c9f40.el7
image-inspector (Red Hat package) - update to 2.1.3-2.el7
golang-github-prometheus-prometheus (Red Hat package) - update to 2.2.1-2.gitbc6058c.el7
openshift-enterprise-image-registry (Red Hat package) - update to 3.8.0-2.git.216.b6b90bb.el7
atomic-openshift-node-problem-detector (Red Hat package) - update to 3.9.13-2.git.167.5d6b0d4.el7
atomic-openshift-descheduler (Red Hat package) - update to 3.9.13-2.git.267.bb59a3f.el7
atomic-openshift (Red Hat package) - addressed in versions 3.9.101-1.git.0.150f595.el7, 3.10.170-1.git.0.8e592d6.el7
atomic-openshift-web-console (Red Hat package) - update to 3.9.101-1.git.1.601c6d2.el7
golang-github-prometheus-node_exporter (Red Hat package) - update to 3.9.101-1.git.1.8295224.el7
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c, 12-2920190821145457.6c81f848, 12-3020190821145457.a5b0195c
BIG-IP LTM - addressed in versions 11.6.5.1, 12.1.5.1, 13.1.3.2, 14.0.1.1, 14.1.2.1, 15.0.1.1, 15.1.0
Twisted Web - update to 19.10.0
cockpit (Red Hat package) - update to 195-2.rhaos.el7
External References
Related Security Bulletins
- Remote denial of service in HTTP/2 implementation in Microsoft Windows
- HTTP/2 Ping Flood vulnerability in F5 Networks BIG-IP LTM
- OpenSUSE Linux update for go1.12
- Arch Linux update for go
- Arch Linux update for go-pie
- Amazon Linux AMI update for golang
- Debian update for h2o
- OpenSUSE Linux update for go1.12
- Debian update for golang-1.11
- OpenSUSE Linux update for go1.11
- OpenSUSE Linux update for go1.12
- Debian update for trafficserver
- OpenSUSE Linux update for nodejs10
- OpenSUSE Linux update for nodejs8
- Red Hat update for Red Hat OpenShift Container Platform 4.1 openshift RPM
- Red Hat update for Red Hat OpenShift Enterprise 4.1.15 gRPC
- Red Hat update for rhel8
- OpenSUSE Linux update for go1.12
- Red Hat update for skydive
- Red Hat update for OpenShift Container Platform 4.1.18 gRPC
- Red Hat update for nodejs:10
- Red Hat update for rh-nodejs10-nodejs
- Red Hat update for go-toolset-1.11 and go-toolset-1.11-golang
- Red Hat update for rh-nodejs8-nodejs
- Red Hat update for Red Hat Quay v3.1.1
- Red Hat update for OpenShift Container Platform 4.1.20 golang
- Red Hat update for OpenShift Container Platform
- Red Hat update for OpenShift Container Platform 4.2
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Multiple vulnerabilities in Red Hat Fuse
- Red Hat update for JBoss Enterprise Application Platform (RHEL 6)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 7)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 8)
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Red Hat update for Single Sign-On 7.3 (RHEL 6)
- Multiple vulnerabilities in Red Hat Single Sign-On
- Red Hat update for Red Hat Single Sign-On 7.3.5 (RHEL 8)
- Red Hat update for Red Hat Single Sign-On 7.3.5 (RHEL 7)
- Red Hat update for container-tools:1.0
- Red Hat update for container-tools:rhel8
- Multiple vulnerabilities in Red Hat JBoss Fuse/A-MQ
- Red Hat update for containernetworking-plugins
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Resource exhaustion in go (Alpine package)
- Resource exhaustion in containerd (Alpine package)
- Resource exhaustion in py3-twisted (Alpine package)
- Resource exhaustion in h2o (Alpine package)
- Resource exhaustion in traefik (Alpine package)
- Resource exhaustion in k3s (Alpine package)
- Denial of service in OpenShift Container Platform 4.1
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in Dell DataIQ
- Red Hat OpenShift Container Platform 3.10 update for atomic-openshift
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 3
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 30 Modular update for nodejs
- Fedora 29 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 Modular update for nodejs
- Fedora 29 update for golang
- Fedora 30 update for golang
- Fedora EPEL 6 update for golang
- Fedora EPEL 7 update for golang
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple HTTP/2 DoS vulnerabilities in Twisted web server