UBUNTU-CVE-2019-9513
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
02 / AFFECTED SOFTWARE
Affected packages
20 explicit affected versions
9 explicit affected versions
12 explicit affected versions
9 explicit affected versions
12 explicit affected versions
8 explicit affected versions
15 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
05 / REFERENCES
Further evidence
- https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
- https://github.com/nodejs/node/pull/29133
- https://github.com/nodejs/node/pull/29148
- https://github.com/nodejs/node/pull/29152
- https://ubuntu.com/security/CVE-2019-9513
- https://ubuntu.com/security/notices/USN-4099-1
- https://ubuntu.com/security/notices/USN-6754-1
- https://www.cve.org/CVERecord?id=CVE-2019-9513