FlawAtlas
Search the atlas
UBUNTU-CVE-2019-9513 High

UBUNTU-CVE-2019-9513

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

Exploit probability Not scored
Published August 13, 2019
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:16.04:LTS nginx

20 explicit affected versions

Ubuntu:18.04:LTS nginx

9 explicit affected versions

Ubuntu:Pro:14.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:16.04:LTS nghttp2

9 explicit affected versions

Ubuntu:Pro:16.04:LTS nodejs

12 explicit affected versions

Ubuntu:Pro:18.04:LTS nghttp2

8 explicit affected versions

Ubuntu:Pro:18.04:LTS nodejs

15 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2019-9513

Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.

View original source

05 / REFERENCES

Further evidence