Resource exhaustion in H2 - CVE-2023-26964
Published: April 16, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when processing processes HTTP2 RST_STREAM frames. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Development Tools Module
openSUSE Leap
rust-ybaas
keyring-ima-signer
rust-pore
rust-sevctl
clevis-pin-tpm2
rust-sequoia-policy-config
rust-below
greetd
rust-cargo-c
rust-gst-plugin-reqwest
rust-git-delta
rust-coreos-installer
rust-sequoia-sq
nispor
rust-rpm-sequoia
rust-sequoia-octopus-librnp
libkrun
rust-tealdeer
rustup
rustup-debuginfo
rustup-debugsource
rust-bodhi-cli
rust-fedora-update-feedback
nmstate
mirrorlist-server
rust-afterburn
How to mitigate CVE-2023-26964
rust-ybaas - addressed in versions 0.0.10-7.fc37, 0.0.10-7.fc38, 0.0.10-7.fc39
keyring-ima-signer - addressed in versions 0.1.0-9.fc37, 0.1.0-9.fc38, 0.1.0-9.fc39
rust-pore - addressed in versions 0.1.8-3.el9, 0.1.8-3.fc37, 0.1.8-3.fc38, 0.1.8-3.fc39
rust-sevctl - addressed in versions 0.3.2-4.fc37, 0.3.2-4.fc38, 0.3.2-4.fc39
clevis-pin-tpm2 - addressed in versions 0.5.2-5.fc37, 0.5.2-5.fc38, 0.5.2-5.fc39
rust-sequoia-policy-config - addressed in versions 0.6.0-3.fc37, 0.6.0-3.fc38, 0.6.0-3.fc39
rust-below - addressed in versions 0.6.3-4.el9, 0.6.3-4.fc37, 0.6.3-4.fc38, 0.6.3-4.fc39
greetd - addressed in versions 0.9.0-4.fc37, 0.9.0-4.fc38, 0.9.0-4.fc39
rust-cargo-c - addressed in versions 0.9.12-4.el9, 0.9.12-4.fc37, 0.9.12-4.fc38, 0.9.12-4.fc39
rust-gst-plugin-reqwest - addressed in versions 0.10.4-2.fc37, 0.10.4-2.fc38, 0.10.4-2.fc39
rust-git-delta - addressed in versions 0.13.0-5.fc37, 0.13.0-5.fc38, 0.13.0-5.fc39
rust-coreos-installer - addressed in versions 0.17.0-2.fc37, 0.17.0-3.fc38, 0.17.0-3.fc39
rust-sequoia-sq - addressed in versions 0.26.0-7.fc37, 0.26.0-7.fc38, 0.26.0-7.fc39
nispor - addressed in versions 1.2.10-4.fc37, 1.2.10-4.fc38, 1.2.10-4.fc39
rust-rpm-sequoia - addressed in versions 1.4.0-2.fc37, 1.4.0-2.fc38, 1.4.0-2.fc39
rust-sequoia-octopus-librnp - addressed in versions 1.4.1-8.fc37, 1.4.1-8.fc38, 1.4.1-8.fc39
libkrun - addressed in versions 1.5.0-2.fc37, 1.5.0-2.fc38, 1.5.0-2.fc39
rust-tealdeer - addressed in versions 1.6.1-2.fc37, 1.6.1-2.fc38, 1.6.1-2.fc39
rustup - update to 1.26.0~0-150400.3.7.1
rustup-debuginfo - update to 1.26.0~0-150400.3.7.1
rustup-debugsource - update to 1.26.0~0-150400.3.7.1
rust-bodhi-cli - addressed in versions 2.1.0-2.fc37, 2.1.0-2.fc38, 2.1.0-2.fc39
rust-fedora-update-feedback - addressed in versions 2.1.2-2.fc37, 2.1.2-2.fc38, 2.1.2-2.fc39
nmstate - addressed in versions 2.2.10-4.fc38, 2.2.10-4.fc39, 2.2.10-5.fc37
mirrorlist-server - addressed in versions 3.0.6-6.fc37, 3.0.6-6.fc38, 3.0.6-6.fc39
rust-afterburn - addressed in versions 5.4.0-3.fc37, 5.4.0-3.fc38, 5.4.0-3.fc39
External References
Related Security Bulletins
- Denial of service in Hyperium H2 library
- SUSE update for rustup
- Fedora 39 update for clevis-pin-tpm2, greetd, keyring-ima-signer, libkrun, mirrorlist-server, nispor, nmstate, rust-afterburn, rust-below, rust-bodhi-cli, rust-cargo-c, rust-coreos-installer, rust-fedora-update-feedback, rust-git-delta, rust-gst-plugin-re
- Fedora 38 update for clevis-pin-tpm2, greetd, keyring-ima-signer, libkrun, mirrorlist-server, nispor, nmstate, rust-afterburn, rust-below, rust-bodhi-cli, rust-cargo-c, rust-coreos-installer, rust-fedora-update-feedback, rust-git-delta, rust-gst-plugin-re
- Fedora 37 update for clevis-pin-tpm2, greetd, keyring-ima-signer, libkrun, mirrorlist-server, nispor, nmstate, rust-afterburn, rust-below, rust-bodhi-cli, rust-cargo-c, rust-coreos-installer, rust-fedora-update-feedback, rust-git-delta, rust-gst-plugin-re
- Fedora EPEL 9 update for rust-below, rust-cargo-c, rust-pore