Resource management error - CVE-2019-9515
Published: August 20, 2019
Vulnerability identifier: #VU20337
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9515
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in HTTP/2 implementation when processing SETTINGS frames. A remote attacker can send a huge amount of SETTINGS frames to the peer and consume excessive CPU and memory on the system.
Affected software
IBM Observability with Instana
IBM PureData System for Operational Analytics
IBM Cloud Transformation Advisor
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Process Mining
IBM Spectrum Protect Storage Agent
runc (Alpine package)
containerd (Alpine package)
h2o (Debian package)
h2o (Alpine package)
trafficserver (Debian package)
py3-twisted (Alpine package)
nodejs
Red Hat Software Collections
Red Hat OpenShift Container Platform
Fuse
AMQ Broker
JBoss Enterprise Application Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat Single Sign-On
IBM Tivoli Application Dependency Discovery Manager
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
BIG-IP LTM
Twisted Web
IBM PureData System for Operational Analytics
IBM Cloud Transformation Advisor
Red Hat OpenStack
Red Hat OpenStack for IBM Power
IBM Process Mining
IBM Spectrum Protect Storage Agent
runc (Alpine package)
containerd (Alpine package)
h2o (Debian package)
h2o (Alpine package)
trafficserver (Debian package)
py3-twisted (Alpine package)
nodejs
Red Hat Software Collections
Red Hat OpenShift Container Platform
Fuse
AMQ Broker
JBoss Enterprise Application Platform
Red Hat Process Automation Manager (formerly JBoss BPM Suite)
Red Hat Single Sign-On
IBM Tivoli Application Dependency Discovery Manager
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
BIG-IP LTM
Twisted Web
How to mitigate CVE-2019-9515
Install updates from vendor's website.
runc (Alpine package) - update to 1.0.0_rc10-r0
containerd (Alpine package) - addressed in versions 1.2.9-r0, 1.3.0-r0, 1.3.3-r0
h2o (Debian package) - update to 2.2.5+dfsg2-2+deb10u1
h2o (Alpine package) - update to 2.2.6-r0
Fuse - addressed in versions 6.3.14, 7.5.0, 7.6.0
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
JBoss Enterprise Application Platform - update to 7.2.5
Red Hat Single Sign-On - update to 7.3.5
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u1
py3-twisted (Alpine package) - update to 20.3.0-r0
IBM Process Mining - update to 1.12.0.4
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c, 12-2920190821145457.6c81f848, 12-3020190821145457.a5b0195c
Twisted Web - update to 19.10.0
containerd (Alpine package) - addressed in versions 1.2.9-r0, 1.3.0-r0, 1.3.3-r0
h2o (Debian package) - update to 2.2.5+dfsg2-2+deb10u1
h2o (Alpine package) - update to 2.2.6-r0
Fuse - addressed in versions 6.3.14, 7.5.0, 7.6.0
AMQ Broker - addressed in versions 7.4.3, 7.6
Red Hat Process Automation Manager (formerly JBoss BPM Suite) - update to 7.8.0
JBoss Enterprise Application Platform - update to 7.2.5
Red Hat Single Sign-On - update to 7.3.5
IBM Tivoli Application Dependency Discovery Manager - update to 7.3.0.7
trafficserver (Debian package) - update to 8.0.2+ds-1+deb10u1
py3-twisted (Alpine package) - update to 20.3.0-r0
IBM Process Mining - update to 1.12.0.4
IBM Spectrum Protect Storage Agent - update to 8.1.19
nodejs - addressed in versions 10.16.3-1.fc29, 10.16.3-1.fc30, 10-2920190816104510.6c81f848, 10-3020190816104510.a5b0195c, 12-2920190821145457.6c81f848, 12-3020190821145457.a5b0195c
Twisted Web - update to 19.10.0
External References
- http://seclists.org/fulldisclosure/2019/Aug/16
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- https://kb.cert.org/vuls/id/605641/
- https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04@%3Cusers.trafficserver.apache.org%3E
- https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19@%3Cannounce.trafficserver.apache.org%3E
- https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7@%3Cdev.trafficserver.apache.org%3E
- https://seclists.org/bugtraq/2019/Aug/24
- https://www.synology.com/security/advisory/Synology_SA_19_33
Related Security Bulletins
- HTTP/2 Settings Flood vulnerability in F5 Networks BIG-IP (LTM)
- Debian update for h2o
- Debian update for trafficserver
- OpenSUSE Linux update for nodejs10
- OpenSUSE Linux update for nodejs8
- Red Hat update for Red Hat OpenShift Enterprise 4.1.15 gRPC
- Red Hat update for skydive
- Red Hat update for OpenShift Container Platform 4.1.18 gRPC
- Red Hat update for nodejs:10
- Red Hat update for rh-nodejs10-nodejs
- Red Hat update for rh-nodejs8-nodejs
- Multiple vulnerabilities in Red Hat Fuse
- Red Hat update for JBoss Enterprise Application Platform (RHEL 6)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 7)
- Red Hat update for JBoss Enterprise Application Platform (RHEL 8)
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform
- Red Hat update for Single Sign-On 7.3 (RHEL 6)
- Multiple vulnerabilities in Red Hat Single Sign-On
- Red Hat update for Red Hat Single Sign-On 7.3.5 (RHEL 8)
- Red Hat update for Red Hat Single Sign-On 7.3.5 (RHEL 7)
- Multiple vulnerabilities in Red Hat JBoss Fuse/A-MQ
- Multiple vulnerabilities in Red Hat Fuse
- Multiple vulnerabilities in Red Hat AMQ Broker
- Multiple vulnerabilities in Red Hat Process Automation Manager
- Resource management error in containerd (Alpine package)
- Resource management error in py3-twisted (Alpine package)
- Resource management error in h2o (Alpine package)
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM Process Mining
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Multiple vulnerabilities in IBM Storage Protect Server
- Multiple vulnerabilities in IBM Observability with Instana (OnPrem)
- Multiple vulnerabilities in AMQ Broker 7.4
- Fedora 30 Modular update for nodejs
- Fedora 29 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 update for nodejs
- Fedora 29 Modular update for nodejs
- Fedora 30 Modular update for nodejs
- Multiple vulnerabilities in IBM Tivoli Application Dependency Discovery Manager
- Multiple HTTP/2 DoS vulnerabilities in Twisted web server