UBUNTU-CVE-2019-9518
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-9518
UBUNTU-CVE-2019-9518
Summary:
Details: Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.
References: https://ubuntu.com/security/CVE-2019-9518, https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md, https://netty.io/news/2019/08/13/4-1-39-Final.html, https://github.com/netty/netty/pull/9461, https://ubuntu.com/security/notices/USN-4866-1, https://www.cve.org/CVERecord?id=CVE-2019-9518
Affected packages
Package
Name: netty
Purl: pkg:deb/ubuntu/netty@1:4.1.7-4ubuntu0.1+esm1?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
