Resource exhaustion in H2 - CVE-2023-26964

 

Resource exhaustion in H2 - CVE-2023-26964

Published: April 16, 2023


Vulnerability identifier: #VU75145
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-26964
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when processing processes HTTP2 RST_STREAM frames. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

H2
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Fedora
Development Tools Module
openSUSE Leap
rust-ybaas
keyring-ima-signer
rust-pore
rust-sevctl
clevis-pin-tpm2
rust-sequoia-policy-config
rust-below
greetd
rust-cargo-c
rust-gst-plugin-reqwest
rust-git-delta
rust-coreos-installer
rust-sequoia-sq
nispor
rust-rpm-sequoia
rust-sequoia-octopus-librnp
libkrun
rust-tealdeer
rustup
rustup-debuginfo
rustup-debugsource
rust-bodhi-cli
rust-fedora-update-feedback
nmstate
mirrorlist-server
rust-afterburn

How to mitigate CVE-2023-26964

Install updates from vendor's website.

H2 - update to 0.3.17
rust-ybaas - addressed in versions 0.0.10-7.fc37, 0.0.10-7.fc38, 0.0.10-7.fc39
keyring-ima-signer - addressed in versions 0.1.0-9.fc37, 0.1.0-9.fc38, 0.1.0-9.fc39
rust-pore - addressed in versions 0.1.8-3.el9, 0.1.8-3.fc37, 0.1.8-3.fc38, 0.1.8-3.fc39
rust-sevctl - addressed in versions 0.3.2-4.fc37, 0.3.2-4.fc38, 0.3.2-4.fc39
clevis-pin-tpm2 - addressed in versions 0.5.2-5.fc37, 0.5.2-5.fc38, 0.5.2-5.fc39
rust-sequoia-policy-config - addressed in versions 0.6.0-3.fc37, 0.6.0-3.fc38, 0.6.0-3.fc39
rust-below - addressed in versions 0.6.3-4.el9, 0.6.3-4.fc37, 0.6.3-4.fc38, 0.6.3-4.fc39
greetd - addressed in versions 0.9.0-4.fc37, 0.9.0-4.fc38, 0.9.0-4.fc39
rust-cargo-c - addressed in versions 0.9.12-4.el9, 0.9.12-4.fc37, 0.9.12-4.fc38, 0.9.12-4.fc39
rust-gst-plugin-reqwest - addressed in versions 0.10.4-2.fc37, 0.10.4-2.fc38, 0.10.4-2.fc39
rust-git-delta - addressed in versions 0.13.0-5.fc37, 0.13.0-5.fc38, 0.13.0-5.fc39
rust-coreos-installer - addressed in versions 0.17.0-2.fc37, 0.17.0-3.fc38, 0.17.0-3.fc39
rust-sequoia-sq - addressed in versions 0.26.0-7.fc37, 0.26.0-7.fc38, 0.26.0-7.fc39
nispor - addressed in versions 1.2.10-4.fc37, 1.2.10-4.fc38, 1.2.10-4.fc39
rust-rpm-sequoia - addressed in versions 1.4.0-2.fc37, 1.4.0-2.fc38, 1.4.0-2.fc39
rust-sequoia-octopus-librnp - addressed in versions 1.4.1-8.fc37, 1.4.1-8.fc38, 1.4.1-8.fc39
libkrun - addressed in versions 1.5.0-2.fc37, 1.5.0-2.fc38, 1.5.0-2.fc39
rust-tealdeer - addressed in versions 1.6.1-2.fc37, 1.6.1-2.fc38, 1.6.1-2.fc39
rustup - update to 1.26.0~0-150400.3.7.1
rustup-debuginfo - update to 1.26.0~0-150400.3.7.1
rustup-debugsource - update to 1.26.0~0-150400.3.7.1
rust-bodhi-cli - addressed in versions 2.1.0-2.fc37, 2.1.0-2.fc38, 2.1.0-2.fc39
rust-fedora-update-feedback - addressed in versions 2.1.2-2.fc37, 2.1.2-2.fc38, 2.1.2-2.fc39
nmstate - addressed in versions 2.2.10-4.fc38, 2.2.10-4.fc39, 2.2.10-5.fc37
mirrorlist-server - addressed in versions 3.0.6-6.fc37, 3.0.6-6.fc38, 3.0.6-6.fc39
rust-afterburn - addressed in versions 5.4.0-3.fc37, 5.4.0-3.fc38, 5.4.0-3.fc39

External References

Related Security Bulletins