Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service
26Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 28%
exploitation probability
28%top 2% of all CVEs
observed exploitation
nono source reports it
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The attacker then sends a stream of requests for a large response object. Depending on how the servers queue the responses, this can consume excess memory, CPU, or both.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/aReferences
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlhttps://access.redhat.com/errata/RHSA-2019:2893https://access.redhat.com/errata/RHSA-2019:2925https://access.redhat.com/errata/RHSA-2019:2939https://access.redhat.com/errata/RHSA-2019:2946https://access.redhat.com/errata/RHSA-2019:2949https://access.redhat.com/errata/RHSA-2019:2950https://access.redhat.com/errata/RHSA-2019:2955https://access.redhat.com/errata/RHSA-2019:3932https://access.redhat.com/errata/RHSA-2019:3933