Back

HIGH

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service

Published Aug 13, 2019

Description

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Affected products

Remediation

Red Hat statement

This issue affects the version of grafana(embeds gRPC) as shipped with Red Hat Ceph Storage 3 as it include the support for HTTP/2. This flaw has no available mitigation for nodejs package. It will be updated once the available fixes are released for Red Hat Enterprise Linux and Red Hat Software Collections. The nodejs RPM shipped in OpenShift Container Platform 3.9 and 3.10 is not affected by this flaw as it does not contain the vulnerable code.

Metrics

References (44)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Aug 13, 2019
Updated Aug 4, 2024
Reserved Mar 1, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 13, 2019