CVE-2019-9516: Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service
A flaw was found in HTTP/2. An attacker, sending a stream of header with a 0-length header name and a 0-length header value, could cause some implementations to allocate memory for these headers and keep the allocations alive until the session dies. The can consume excess memory, potentially leading to a denial of service. The highest threat from this vulnerability is to system availability.
Other sources
A vulnerability was found in http/2 where an attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory, potentially leading to a denial of service.
— Red Hat
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and keep the allocation alive until the session dies. This can consume excess memory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.29-41.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-1.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el6 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.29-41.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-1.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-aprto a version that resolves this vulnerability.Fixed in 0:1.6.3-63.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-apr-utilto a version that resolves this vulnerability.Fixed in 0:1.6.1-48.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-brotlito a version that resolves this vulnerability.Fixed in 0:1.0.6-7.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-curlto a version that resolves this vulnerability.Fixed in 0:7.64.1-14.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-33.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-janssonto a version that resolves this vulnerability.Fixed in 0:2.11-20.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-nghttp2to a version that resolves this vulnerability.Fixed in 0:1.39.2-4.jbcs.el7 - Upgrade
Upgrade
redhat/jbcs-httpd24-opensslto a version that resolves this vulnerability.Fixed in 1:1.1.1-25.jbcs.el7 - Upgrade
Upgrade
redhat/rh-nginx110-nginxto a version that resolves this vulnerability.Fixed in 1:1.10.2-9.el6.1 - Upgrade
Upgrade
redhat/rh-nginx110-nginxto a version that resolves this vulnerability.Fixed in 1:1.10.2-9.el7.1 - Upgrade
Upgrade
redhat/rh-nginx112-nginxto a version that resolves this vulnerability.Fixed in 1:1.12.1-3.el7.1 - Upgrade
Upgrade
redhat/rh-nginx114-nginxto a version that resolves this vulnerability.Fixed in 1:1.14.1-1.el7.1 - Upgrade
Upgrade
redhat/rh-nodejs10to a version that resolves this vulnerability.Fixed in 0:3.2-3.el7 - Upgrade
Upgrade
redhat/rh-nodejs10-nodejsto a version that resolves this vulnerability.Fixed in 0:10.16.3-3.el7 - Upgrade
Upgrade
redhat/rh-nodejs8to a version that resolves this vulnerability.Fixed in 0:3.0-5.el7 - Upgrade
Upgrade
redhat/rh-nodejs8-nodejsto a version that resolves this vulnerability.Fixed in 0:8.16.1-2.el7 - Upgrade
Upgrade
debian/nginxto a version that resolves this vulnerability.Fixed in 1.18.0-6.1+deb11u3Fixed in 1.18.0-6.1+deb11u5Fixed in 1.22.1-9+deb12u3Fixed in 1.22.1-9+deb12u4Fixed in 1.26.3-3+deb13u1Fixed in 1.26.3-3+deb13u2Fixed in 1.28.2-2 - Upgrade
Upgrade
redhat/Nodejsto a version that resolves this vulnerability.Fixed in 8.16.1 - Upgrade
Upgrade
redhat/Nodejsto a version that resolves this vulnerability.Fixed in 10.16.3 - Upgrade
Upgrade
redhat/Nodejsto a version that resolves this vulnerability.Fixed in 12.8.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.16.1 - Upgrade
Upgrade
redhat/nginxto a version that resolves this vulnerability.Fixed in 1.17.3 - Configuration
Edit the Nginx configuration (nginx.conf) to remove/disable HTTP/2 support by changing it to not use `http2` (e.g., run `sed -i 's/http2 //g' /mnt/quay/nginx/nginx.conf` and then restart Nginx with the updated config mounted into the container).
Nginx (inside Red Hat Quay 3.0 container) http2 = disabled
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-9516?
CVE-2019-9516 is a vulnerability in HTTP/2 that allows an attacker to cause a denial of service.
How does CVE-2019-9516 work?
CVE-2019-9516 works by sending a stream of headers with 0-length header names and values, potentially causing a header leak and leading to a denial of service.
Which software is affected by CVE-2019-9516?
Node.js versions up to 8.16.1, 10.16.3, and 12.8.1, as well as Nginx versions 1.16.1 and 1.17.3 are affected by CVE-2019-9516.
How severe is CVE-2019-9516?
CVE-2019-9516 has a severity rating of high, with a CVSS score of 6.5.
Are there any references for CVE-2019-9516?
Yes, you can find references for CVE-2019-9516 in the following links: [link1], [link2], [link3].