Denial of service in nghttp2
Published Jun 3, 2020
7.5
HIGHCVSS 3.1
EPSS 5.32%
Description
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vulnerability. There is a workaround to this vulnerability. Implement nghttp2_on_frame_recv_callback callback, and if received frame is SETTINGS frame and the number of settings entries are large (e.g., > 32), then drop the connection.
Affected products
-
- Version < 1.41.0StatusaffectedConstraints-
- Version
Configuration 2
- 9.0
- 10.0
Configuration 4
- 31
- 33
Configuration 5
- 14.3.0
- 14.4.0
- < 21.1.2
- 3.1.0
- 3.2.0
- 19.3.2
- 20.1.0
- ≥ 7.3.0 · ≤ 7.3.30
- ≥ 7.4.0 · ≤ 7.4.29
- ≥ 7.5.0 · ≤ 7.5.19
- ≥ 7.6.0 · ≤ 7.6.15
- ≥ 8.0.0 · ≤ 8.0.21
No data.
JBoss Core Services on RHEL 6
jbcs-httpd24-curl-0:7.64.1-36.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 6
jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el6
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-curl-0:7.64.1-36.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el7
Fixed · RHSA-2020:2644
JBoss Core Services on RHEL 7
jbcs-httpd24-openssl-pkcs11-0:0.4.10-7.jbcs.el7
Fixed · RHSA-2020:2644
OpenShift Service Mesh 1.0
servicemesh-proxy-0:1.0.10-3.el8
Fixed · RHSA-2020:2524
OpenShift Service Mesh 1.1
servicemesh-proxy-0:1.1.2-3.el8
Fixed · RHSA-2020:2523
Red Hat Enterprise Linux 8
nghttp2-0:1.33.0-3.el8_2.1
Fixed · RHSA-2020:2755
Red Hat Enterprise Linux 8
nodejs:10-8020020200617141353.4cda2c84
Fixed · RHSA-2020:2848
Red Hat Enterprise Linux 8
nodejs:12-8020020200630155331.4cda2c84
Fixed · RHSA-2020:2852
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
nghttp2-0:1.33.0-1.el8_0.2
Fixed · RHSA-2020:2850
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
nodejs:10-8000020200617115915.f8e95b4e
Fixed · RHSA-2020:3042
Red Hat Enterprise Linux 8.1 Extended Update Support
nghttp2-0:1.33.0-3.el8_1.1
Fixed · RHSA-2020:2823
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:10-8010020200617134056.c27ad7f8
Fixed · RHSA-2020:2849
Red Hat Enterprise Linux 8.1 Extended Update Support
nodejs:12-8010020200630154708.c27ad7f8
Fixed · RHSA-2020:2847
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2020:2646
Red Hat Software Collections for Red Hat Enterprise Linux 6
httpd24-nghttp2-0:1.7.1-8.el6.1
Fixed · RHSA-2020:2784
Red Hat Software Collections for Red Hat Enterprise Linux 7
httpd24-nghttp2-0:1.7.1-8.el7.1
Fixed · RHSA-2020:2784
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
httpd24-nghttp2-0:1.7.1-8.el7.1
Fixed · RHSA-2020:2784
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
httpd24-nghttp2-0:1.7.1-8.el7.1
Fixed · RHSA-2020:2784
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs10-nodejs-0:10.21.0-3.el7
Fixed · RHSA-2020:3084
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
rh-nodejs12-nodejs-0:12.18.2-1.el7
Fixed · RHSA-2020:2895
Red Hat Enterprise Linux 8
nodejs:14/nodejs
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services on RHEL 6 | jbcs-httpd24-curl-0:7.64.1-36.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 6 | jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el6 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-curl-0:7.64.1-36.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-57.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.14-4.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-3.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-4.redhat_1.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-24.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-51.GA.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-nghttp2-0:1.39.2-25.jbcs.el7 | Fixed | RHSA-2020:2644 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-openssl-pkcs11-0:0.4.10-7.jbcs.el7 | Fixed | RHSA-2020:2644 |
| OpenShift Service Mesh 1.0 | servicemesh-proxy-0:1.0.10-3.el8 | Fixed | RHSA-2020:2524 |
| OpenShift Service Mesh 1.1 | servicemesh-proxy-0:1.1.2-3.el8 | Fixed | RHSA-2020:2523 |
| Red Hat Enterprise Linux 8 | nghttp2-0:1.33.0-3.el8_2.1 | Fixed | RHSA-2020:2755 |
| Red Hat Enterprise Linux 8 | nodejs:10-8020020200617141353.4cda2c84 | Fixed | RHSA-2020:2848 |
| Red Hat Enterprise Linux 8 | nodejs:12-8020020200630155331.4cda2c84 | Fixed | RHSA-2020:2852 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nghttp2-0:1.33.0-1.el8_0.2 | Fixed | RHSA-2020:2850 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | nodejs:10-8000020200617115915.f8e95b4e | Fixed | RHSA-2020:3042 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nghttp2-0:1.33.0-3.el8_1.1 | Fixed | RHSA-2020:2823 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:10-8010020200617134056.c27ad7f8 | Fixed | RHSA-2020:2849 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | nodejs:12-8010020200630154708.c27ad7f8 | Fixed | RHSA-2020:2847 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2020:2646 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | httpd24-nghttp2-0:1.7.1-8.el6.1 | Fixed | RHSA-2020:2784 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | httpd24-nghttp2-0:1.7.1-8.el7.1 | Fixed | RHSA-2020:2784 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | httpd24-nghttp2-0:1.7.1-8.el7.1 | Fixed | RHSA-2020:2784 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | httpd24-nghttp2-0:1.7.1-8.el7.1 | Fixed | RHSA-2020:2784 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs10-nodejs-0:10.21.0-3.el7 | Fixed | RHSA-2020:3084 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | rh-nodejs12-nodejs-0:12.18.2-1.el7 | Fixed | RHSA-2020:2895 |
| Red Hat Enterprise Linux 8 | nodejs:14/nodejs | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html vendor-advisoryMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2020-11080 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1844929 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-3444 Advisory
- https://github.com/nghttp2/nghttp2/commit/336a98feb0d56b9ac54e12736b18785c27f75090 PatchThird Party Advisory
- https://github.com/nghttp2/nghttp2/commit/f8da73bd042f810f34d19f9eae02b46d870af394 PatchThird Party Advisory
- https://github.com/nghttp2/nghttp2/security/advisories/GHSA-q5wr-xfw9-q7xr PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/10/msg00011.html mailing-listMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html mailing-list
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4OOYAMJVLLCLXDTHW3V5UXNULZBBK4O6/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AAC2AA36OTRHKSVM5OV7TTVB3CZIGEFL/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-11080
- https://www.cve.org/CVERecord?id=CVE-2020-11080
- https://www.debian.org/security/2020/dsa-4696 vendor-advisoryThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html Not ApplicableThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html Third Party Advisory
Change history (0)
No recorded changes yet.