CERT/CC disclosed eight HTTP/2 denial-of-service weaknesses involving abnormal traffic and resource exhaustion. gRPC implementations were affected by CVE-2019-9512 (Ping Flood), CVE-2019-9514 (Reset Flood), and CVE-2019-9515 (Settings Flood), which allow malicious peers to send excessive HTTP/2 frames and drive unbounded memory consumption or otherwise exhaust service resources.
Fixes were released for gRPC-Go and gRPC-Java, while remediation for gRPC-C and languages wrapping it was underway; users were urged to upgrade promptly. Istio released version 1.2.4, and Red Hat patched the affected gRPC component in the sriov-network-device-plugin container through OpenShift Container Platform 4.1.18; OpenShift 4.1 operators should upgrade clusters to receive the fixes.

See affected versions and whether adversaries are exploiting it.
34 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2020:2992 for OpenShift Container Platform 3.11 and OpenShift Container Platform for Power 3.11. The update provided atomic-openshift, atomic-openshift-web-console, and CRI-O packages to remediate CVE-2019-14891, CVE-2020-7598, CVE-2020-8552, CVE-2020-8558, CVE-2020-8945, and CVE-2020-10715.
CVE-2020-7598, a moderate-severity prototype-pollution vulnerability in nodejs-minimist, was publicly disclosed. Crafted "constructor" or "__proto__" inputs could modify Object.prototype properties and potentially affect confidentiality, integrity, or availability.
Red Hat issued Important advisory RHSA-2020:0406 for containernetworking-plugins in RHEL 7 Extras. The update supplied version 0.8.1-4.el7_7 for affected architectures and remediated HTTP/2 PING- and HEADERS-frame flood flaws CVE-2019-9512 and CVE-2019-9514.
Red Hat issued Important advisory RHSA-2019:4273 for the container-tools:1.0 module in Red Hat Enterprise Linux 8. The update remediated HTTP/2 PING- and HEADERS-frame flood denial-of-service vulnerabilities CVE-2019-9512 and CVE-2019-9514 for affected RHEL 8 architectures.
Red Hat issued Important advisory RHSA-2019:3935 for JBoss Core Services Apache HTTP Server 2.4.37, replacing version 2.4.29 in ZIP packages for RHEL 6, RHEL 7, and Microsoft Windows. The update remediated OpenSSL and Apache HTTP Server flaws as well as HTTP/2 denial-of-service vulnerabilities CVE-2019-9511, CVE-2019-9513, CVE-2019-9516, and CVE-2019-9517.
Red Hat issued Important advisory RHSA-2019:3933 for JBoss Core Services 1 Apache HTTP Server on RHEL 7 x86_64, replacing Apache Server 2.4.29 with 2.4.37 packages. The update remediated multiple OpenSSL, Apache HTTP Server, and HTTP/2 flaws, including nghttp2 CVE-2019-9511 and CVE-2019-9513 and mod_http2 CVE-2019-9516 and CVE-2019-9517.
Red Hat issued Important advisory RHSA-2019:3906 for OpenShift Container Platform 3.11 and OpenShift Container Platform for Power 3.11. The update rebuilt affected OpenShift RPMs with an updated Go version to remediate HTTP/2 PING- and HEADERS-frame flood vulnerabilities CVE-2019-9512 and CVE-2019-9514.
Red Hat issued Important advisory RHSA-2019:3245 for OpenShift Container Platform 4.2 on RHEL 7 x86_64. The update rebuilt apb, containernetworking-plugins, and golang-github-prometheus-promu with an updated Go version to remediate HTTP/2 PING- and HEADERS-frame flood flaws CVE-2019-9512 and CVE-2019-9514.
Red Hat issued Important advisory RHSA-2019:2769 for OpenShift Container Platform 3.9 on x86_64, providing packages rebuilt with updated Go. The update remediated HTTP/2 PING- and HEADERS-frame flood vulnerabilities CVE-2019-9512 and CVE-2019-9514, along with Kubernetes API-server authorization flaw CVE-2019-11247; users were directed to upgrade to OpenShift 3.9.100 or later.
Red Hat issued Important advisory RHSA-2019:3131 for OpenShift Container Platform 4.1.20, rebuilding cri-o, cri-tools, ignition, pivot, and other OpenShift RPMs with an updated Go version. The update remediated HTTP/2 PING- and HEADERS-frame flood vulnerabilities CVE-2019-9512 and CVE-2019-9514 for affected RHEL 7 and RHEL 8 x86_64 deployments.
Red Hat issued Important advisory RHSA-2019:3041 for OpenShift Service Mesh 1.0.1 RPM packages on RHEL 7 and RHEL 8 x86_64. The update remediated HTTP/2 denial-of-service vulnerabilities CVE-2019-9511 and CVE-2019-9513.
Red Hat issued Important advisory RHSA-2019:2966 for Red Hat Quay Enterprise 3, releasing Quay 3.1.1 to remediate HTTP/2 denial-of-service flaws CVE-2019-9511, CVE-2019-9512, CVE-2019-9513, CVE-2019-9514, and CVE-2019-9516. Updated Quay, Clair JWT, and Quay Builder container images were made available with the v3.1.1 tag.
Red Hat issued Important advisory RHSA-2019:2949 for httpd24-httpd and httpd24-nghttp2 in Red Hat Software Collections on RHEL 6 and 7. The updates remediated HTTP/2 denial-of-service vulnerabilities CVE-2019-9511, CVE-2019-9513, and CVE-2019-9517.
Red Hat issued Important advisory RHSA-2019:2950 for JBoss Core Services Apache HTTP Server 2.4.29 Service Pack 3, replacing Service Pack 2. The update remediated mod_http2 HTTP/2 denial-of-service vulnerabilities CVE-2019-9516 and CVE-2019-9517, rebased nghttp2 to 1.39.2, and supplied packages for RHEL 6, RHEL 7, Microsoft Windows, and Oracle Solaris.
Red Hat issued Important advisory RHSA-2019:2946 for JBoss Core Services Apache HTTP Server 2.4.29 Service Pack 3 on RHEL 6 and RHEL 7. The update remediated mod_http2 denial-of-service flaws CVE-2019-9516 and CVE-2019-9517, rebased nghttp2 to 1.39.2, and supplied Apache HTTP Server 2.4.29-41.jbcs packages.
Red Hat issued an Important security advisory for OpenShift Container Platform 4.1.18, updating gRPC in the sriov-network-device-plugin container. The update addressed CVE-2019-9512, CVE-2019-9514, and CVE-2019-9515 and instructed users to upgrade their clusters to 4.1.18.
Red Hat issued Important advisory RHSA-2019:2799 for the nginx:1.14 module in Red Hat Enterprise Linux 8. The update remediated HTTP/2 denial-of-service vulnerabilities CVE-2019-9511, CVE-2019-9513, and CVE-2019-9516 across affected RHEL 8 architectures and channels.
Red Hat issued Important advisory RHSA-2019:2775 for rh-nginx114-nginx in Red Hat Software Collections for RHEL 7. The update supplied rh-nginx114-nginx 1.14.1-1.el7.1 and remediated HTTP/2 denial-of-service vulnerabilities CVE-2019-9511, CVE-2019-9513, and CVE-2019-9516.
Red Hat issued Important advisory RHSA-2019:2745 for rh-nginx110-nginx in Red Hat Software Collections on RHEL 6 and 7. The update supplied rh-nginx110-nginx 1.10.2-9.el6.1 and 1.10.2-9.el7.1 to remediate HTTP/2 denial-of-service flaws CVE-2019-9511, CVE-2019-9513, and CVE-2019-9516.
Red Hat issued Important advisory RHSA-2019:2690 for atomic-openshift in OpenShift Container Platform 3.10. The 3.10.170 update remediated HTTP/2 PING- and HEADERS-frame flood flaws CVE-2019-9512 and CVE-2019-9514, plus Kubernetes API server authorization flaw CVE-2019-11247.
Red Hat closed its tracking bug for CVE-2019-9513, an HTTP/2 PRIORITY-frame flood issue that can cause excessive CPU consumption and starve clients. The remediation record included fixes or advisories for RHEL, Software Collections, Red Hat Quay, OpenShift Service Mesh, JBoss Core Services, and Red Hat Fuse; Quay users were advised to disable HTTP/2 in NGINX pending updates.
Red Hat issued Important advisory RHSA-2019:2692 for nghttp2 on Red Hat Enterprise Linux 8. The update supplied nghttp2 and libnghttp2 1.33.0-1.el8_0.1 to remediate HTTP/2 denial-of-service vulnerabilities CVE-2019-9511 and CVE-2019-9513 across supported RHEL 8 and CodeReady Linux Builder architectures.
In nghttp2 issue #1382, the project confirmed that version 1.39.2 remediated CVE-2019-9511 and CVE-2019-9513. Maintainer Tatsuhiro Tsujikawa also stated that nghttp2 was not affected by the other HTTP/2 vulnerabilities in the August 2019 eight-flaw set at that time.
The Go project addressed CVE-2019-9512 and CVE-2019-9514 in net/http and golang.org/x/net/http2 by updating the bundled HTTP/2 implementation and closing connections whose send queues accumulate excessive control messages. The flaws could let an unauthenticated client exhaust memory and crash an affected directly exposed server; Jonathan Looney of Netflix reported them.
Red Hat released an Important-security-impact update for OpenShift Container Platform 4.1, providing version 4.1.14 container images rebuilt with updated Go versions. The update remediated the HTTP/2 PING- and HEADERS-frame flood vulnerabilities CVE-2019-9512 and CVE-2019-9514, and fixed a web-console ClusterResourceQuota listing defect.
Red Hat tracked CVE-2019-9517, in which an attacker keeps the TCP receive window closed while requesting large HTTP/2 responses, causing servers to queue unsent data and exhaust memory or CPU. It identified affected httpd/mod_http2, nghttp2, Node.js, nginx, and Undertow implementations; advised disabling HTTP/2 on RHEL 8 pending mod_http2 updates; and issued remediation advisories for RHEL, Software Collections, JBoss Core Services, AMQ, and Fuse.
Red Hat documented CVE-2019-9514, in which invalid HTTP HEADERS frames cause RST_STREAM responses to queue and can lead to unbounded memory growth and denial of service. It identified affected Go-, Node.js-, and HTTP/2-enabled products and issued advisories across RHEL, OpenShift, Ceph, Gluster, Quay, middleware, and other offerings; no mitigation was available for golang and nodejs packages pending platform fixes.
Netty announced the release of version 4.1.39.Final. The provided reference metadata does not specify the vulnerabilities addressed by the release.
Red Hat released RHSA-2019:3932 to fix CVE-2019-9511 in additional affected JBoss Core Services on RHEL 6 components, including jbcs-httpd24-apr, apr-util, brotli, curl, httpd, jansson, mod_cluster-native, and mod_jk.
Red Hat tracked CVE-2019-9516, in which HTTP/2 streams containing zero-length header names and values can cause persistent memory allocations and denial of service. It identified upstream fixes for Node.js, NGINX, and mod_http2, issued advisories across RHEL, Software Collections, JBoss Core Services, Quay, AMQ, and Fuse, and advised Quay 3.0 users to disable HTTP/2 in NGINX pending fixes.
Red Hat documented CVE-2019-9512, in which PING-frame floods can queue PING ACK responses and cause unbounded memory growth in vulnerable HTTP/2 implementations. It identified affected Go-, Node.js-, gRPC-, and HTTP/2-enabled products across OpenShift, Ceph, Gluster, OpenStack, Quay, and middleware, and later issued advisories across those product lines.
Red Hat tracked CVE-2019-9511, an HTTP/2 flaw where manipulated flow-control windows and stream priorities can make servers queue response data in one-byte chunks, exhausting CPU or memory. It recorded fixes across httpd, mod_http2, nghttp2, Node.js, NGINX, Undertow, and numerous Red Hat product lines; Quay 3.0 users were temporarily advised to disable HTTP/2 in NGINX pending fixed releases.
gRPC-Go released fixes in versions 1.23.0, 1.22.2, and 1.21.3, while gRPC-Java released fixes in versions 1.23.0, 1.22.2, and 1.21.1. Fixes for gRPC-C and wrapped languages were still in progress.
CERT Vulnerability Note VU#605641 disclosed eight denial-of-service flaws in HTTP/2 implementations. gRPC implementations were identified as potentially affected by Ping Flood (CVE-2019-9512), Reset Flood (CVE-2019-9514), and Settings Flood (CVE-2019-9515).
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcekb.cert.org
Open sourcemail-archive.com
Open sourceistio.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.