CVE-2019-9513: Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service
A flaw was found in HTTP/2. An attacker, using PRIORITY frames to flood the system, could cause excessive CPU usage and starvation of other clients. The largest threat from this vulnerability is to system availability.
Other sources
HTTP/2 flood using PRIORITY frames that results in excessive CPU usage and starvation of other clients.
— Red Hat
Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.29-41.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-1.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.29-41.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-1.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el7 - Upgrade
Upgrade
redhat/kialito a version that resolves this vulnerability.Fixed in 0:v1.0.6.redhat1-1.el7 - Upgrade
Upgrade
redhat/servicemeshto a version that resolves this vulnerability.Fixed in 0:1.0.1-8.el8 - Upgrade
Upgrade
redhat/servicemesh-cnito a version that resolves this vulnerability.Fixed in 0:1.0.1-8.el8 - Upgrade
Upgrade
redhat/servicemesh-grafanato a version that resolves this vulnerability.Fixed in 0:6.2.2-21.el8 - Upgrade
Upgrade
redhat/servicemesh-operatorto a version that resolves this vulnerability.Fixed in 0:1.0.1-8.el8 - Upgrade
Upgrade
redhat/servicemesh-prometheusto a version that resolves this vulnerability.Fixed in 0:2.7.2-22.el8 - Upgrade
Upgrade
redhat/servicemesh-proxyto a version that resolves this vulnerability.Fixed in 0:1.0.1-7.el8 - Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 0:1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/rh-nginx110-nginxto a version that resolves this vulnerability.Fixed in 1:1.10.2-9.el6.1 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-8.el6.1 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-7.el6.1 - Upgrade
Upgrade
redhat/rh-nginx110-nginxto a version that resolves this vulnerability.Fixed in 1:1.10.2-9.el7.1 - Upgrade
Upgrade
redhat/rh-nginx112-nginxto a version that resolves this vulnerability.Fixed in 1:1.12.1-3.el7.1 - Upgrade
Upgrade
redhat/rh-nginx114-nginxto a version that resolves this vulnerability.Fixed in 1:1.14.1-1.el7.1 - Upgrade
Upgrade
redhat/rh-nodejs10to a version that resolves this vulnerability.Fixed in 0:3.2-3.el7 - Upgrade
Upgrade
redhat/rh-nodejs10-nodejsto a version that resolves this vulnerability.Fixed in 0:10.16.3-3.el7 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-8.el7.1 - Upgrade
Upgrade
redhat/httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.7.1-7.el7.1 - Upgrade
Upgrade
redhat/rh-nodejs8to a version that resolves this vulnerability.Fixed in 0:3.0-5.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-nodejsto a version that resolves this vulnerability.Fixed in 0:8.16.1-2.el7 - Upgrade
Upgrade
debian/nghttp2to a version that resolves this vulnerability.Fixed in 1.43.0-1+deb11u1Fixed in 1.43.0-1+deb11u2Fixed in 1.52.0-1+deb12u2Fixed in 1.52.0-1+deb12u1Fixed in 1.64.0-1.1Fixed in 1.68.0-1 - Upgrade
Upgrade
debian/nginxto a version that resolves this vulnerability.Fixed in 1.18.0-6.1+deb11u3Fixed in 1.18.0-6.1+deb11u5Fixed in 1.22.1-9+deb12u3Fixed in 1.22.1-9+deb12u4Fixed in 1.26.3-3+deb13u1Fixed in 1.26.3-3+deb13u2Fixed in 1.28.2-2 - Upgrade
Upgrade
debian/nodejsto a version that resolves this vulnerability.Fixed in 12.22.12~dfsg-1~deb11u4Fixed in 12.22.12~dfsg-1~deb11u7Fixed in 18.20.4+dfsg-1~deb12u1Fixed in 20.19.2+dfsg-1Fixed in 22.22.0+dfsg+~cs22.19.6-1 - Upgrade
Upgrade
redhat/envoyto a version that resolves this vulnerability.Fixed in 1.11.1 - Upgrade
Upgrade
redhat/Nodejsto a version that resolves this vulnerability.Fixed in 8.16.1 - Upgrade
Upgrade
redhat/Nodejsto a version that resolves this vulnerability.Fixed in 10.16.3 - Upgrade
Upgrade
redhat/Nodejsto a version that resolves this vulnerability.Fixed in 12.8.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.17.3 - Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.39.2 - Configuration
For Red Hat Quay 3.0 (uses Nginx 1.12 from Red Hat Software Collections), edit the Nginx configuration (e.g., /mnt/quay/nginx/nginx.conf) to remove HTTP/2 support; as shown, run: sed -i 's/http2 //g' /mnt/quay/nginx/nginx.conf, using the host-mounted Nginx config copied from the quay container.
Red Hat Quay (nginx within quay.io/redhat/quay:v3.0.3 container) HTTP/2 support in Nginx configuration (nginx.conf) = http2 disabled (remove http2)
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-9513?
The severity of CVE-2019-9513 is critical due to its potential impact on system availability and resource exhaustion.
How do I fix CVE-2019-9513?
To fix CVE-2019-9513, you should upgrade to the latest versions of the affected software packages as specified in the security advisories.
What are the impacted products associated with CVE-2019-9513?
Products affected by CVE-2019-9513 include various versions of Apache HTTP Server, nghttp2, and several other software packages related to HTTP/2 implementation.
Who is affected by CVE-2019-9513?
Any systems utilizing affected versions of HTTP/2 implementations, especially in web server environments, are vulnerable to CVE-2019-9513.
Is there a workaround for CVE-2019-9513?
Currently, the recommended action is to apply the relevant patches, as there are no known effective workarounds for CVE-2019-9513.