Bugzilla – Bug 1146115
VUL-0: CVE-2019-9514: go: HTTP/2 implementation is vulnerable to a reset flood, potentially leading to a denial of service
Last modified: 2019-11-06 23:55:02 UTC
+++ This bug was initially created as a clone of Bug #1145663 +++ CVE-2019-9514 Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-9514 http://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-9514.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-9514 http://www.cvedetails.com/cve/CVE-2019-9514/ https://seclists.org/bugtraq/2019/Aug/24 https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md https://kb.cert.org/vuls/id/605641/ https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7@%3Cdev.trafficserver.apache.org%3E https://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19@%3Cannounce.trafficserver.apache.org%3E https://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04@%3Cusers.trafficserver.apache.org%3E
SUSE-SU-2019:2213-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1141688,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): go1.11-1.11.13-1.18.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): go1.11-1.11.13-1.18.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2019:2214-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): go1.12-1.12.9-1.15.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): go1.12-1.12.9-1.15.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2000-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (important) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.9.1
openSUSE-SU-2019:2056-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.13.1 openSUSE Leap 15.0 (src): go1.12-1.12.9-lp150.8.1
openSUSE-SU-2019:2072-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1141688,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.11-1.11.13-lp151.2.9.1 openSUSE Leap 15.0 (src): go1.11-1.11.13-lp150.18.1
openSUSE-SU-2019:2085-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.17.1
openSUSE-SU-2019:2130-1: An update that solves three vulnerabilities and has two fixes is now available. Category: security (moderate) Bug References: 1139210,1141689,1146111,1146115,1146123 CVE References: CVE-2019-14809,CVE-2019-9512,CVE-2019-9514 Sources used: openSUSE Leap 15.1 (src): go1.12-1.12.9-lp151.2.21.1
I think we can close that as fixed now.