RHSA-2019:2692: Important: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): HTTP/2: large amount of data request leads to denial of service (CVE-2019-9511) HTTP/2: flood using PRIORITY frames resulting in excessive resource consumption (CVE-2019-9513) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/libnghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1.aa - Upgrade
Upgrade
redhat/libnghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1.aa - Upgrade
Upgrade
redhat/nghttp2-debuginfoto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1.aa - Upgrade
Upgrade
redhat/nghttp2-debugsourceto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1.aa - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1 - Upgrade
Upgrade
redhat/libnghttp2-develto a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1.aa - Upgrade
Upgrade
redhat/nghttp2to a version that resolves this vulnerability.Fixed in 1.33.0-1.el8_0.1.aa - Upgrade
Upgrade
nghttp2to a version that resolves this vulnerability.Fixed in nghttp2-1.33.0-1.el8_0.1 - Upgrade
Upgrade
libnghttp2to a version that resolves this vulnerability.Fixed in libnghttp2-1.33.0-1.el8_0.1 - Upgrade
Upgrade
nghttp2-develto a version that resolves this vulnerability.Fixed in libnghttp2-devel-1.33.0-1.el8_0.1 - Upgrade
Upgrade
nghttp2 (source RPM)to a version that resolves this vulnerability.Fixed in nghttp2-1.33.0-1.el8_0.1.src
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:2692?
The severity of RHSA-2019:2692 is classified as a denial of service vulnerability.
How do I fix RHSA-2019:2692?
To fix RHSA-2019:2692, update to libnghttp2 and nghttp2 versions 1.33.0-1.el8_0.1 or later.
What is the impact of RHSA-2019:2692?
The impact of RHSA-2019:2692 can lead to service disruption due to excessive resource consumption.
Which software packages are affected by RHSA-2019:2692?
The affected software packages include libnghttp2, nghttp2, and their debuginfo versions.
Is there a workaround for RHSA-2019:2692?
There is no specific workaround for RHSA-2019:2692; updating is the recommended approach.