UBUNTU-CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
02 / AFFECTED SOFTWARE
Affected packages
4 explicit affected versions
11 explicit affected versions
11 explicit affected versions
6 explicit affected versions
2 explicit affected versions
4 explicit affected versions
5 explicit affected versions
3 explicit affected versions
9 explicit affected versions
3 explicit affected versions
17 explicit affected versions
8 explicit affected versions
14 explicit affected versions
13 explicit affected versions
7 explicit affected versions
2 explicit affected versions
9 explicit affected versions
5 explicit affected versions
2 explicit affected versions
4 explicit affected versions
11 explicit affected versions
2 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
05 / REFERENCES
Further evidence
- https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/
- https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/
- https://blog.powerdns.com/2024/02/16/powerdns-dnsdist-1.9.0-released
- https://devblogs.microsoft.com/dotnet/october-2023-updates/
- https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0
- https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo
- https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q
- https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html
- https://mailman.powerdns.com/pipermail/dnsdist/2023-October/001409.html
- https://my.f5.com/manage/s/article/K000137106
- https://nodejs.org/en/blog/vulnerability/october-2023-security-releases
- https://tomcat.apache.org/security-8.html
- https://ubuntu.com/security/CVE-2023-44487
- https://ubuntu.com/security/notices/USN-6427-1
- https://ubuntu.com/security/notices/USN-6427-2
- https://ubuntu.com/security/notices/USN-6438-1
- https://ubuntu.com/security/notices/USN-6505-1
- https://ubuntu.com/security/notices/USN-6574-1
- https://ubuntu.com/security/notices/USN-6754-1
- https://ubuntu.com/security/notices/USN-6994-1
- https://ubuntu.com/security/notices/USN-7067-1
- https://ubuntu.com/security/notices/USN-7410-1
- https://ubuntu.com/security/notices/USN-7469-1
- https://ubuntu.com/security/notices/USN-7469-2
- https://ubuntu.com/security/notices/USN-7469-3
- https://ubuntu.com/security/notices/USN-7469-4
- https://ubuntu.com/security/notices/USN-7892-1
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cve.org/CVERecord?id=CVE-2023-44487
- https://www.mail-archive.com/[email protected]/msg44134.html
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/