Back

HIGH

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service

Published Aug 13, 2019

Description

Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each frame disproportionate to attack bandwidth. This can consume excess CPU.

Affected products

Remediation

Red Hat statement

This flaw has no available mitigation for nodejs package. It will be updated once the available fixes are released for Red Hat Enterprise Linux and Red Hat Software Collections. The nodejs RPM shipped in OpenShift Container Platform 3.9 and 3.10 is not affected by this flaw as it does not contain the vulnerable code.

Metrics

References (32)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner certcc
Published Aug 13, 2019
Updated Aug 4, 2024
Reserved Mar 1, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Aug 13, 2019