CVE-2018-16843
published 2018-11-07CVE-2018-16843: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
47.06%
98.7th percentile
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 13.0 | 13.0 |
| apple | xcode | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.14.1-1 (bookworm) | nginx 1.14.1-1 (bookworm) |
| f5 | nginx | < 1.14.1 | 1.14.1 |
| f5 | nginx | < 1.15.6 | 1.15.6 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3.9 | 1.4.6-1ubuntu3.9 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.3 | 1.10.3-0ubuntu0.16.04.3 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.2 | 1.14.0-0ubuntu1.2 |
| opensuse | leap | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability is only exploitable when nginx is compiled with ngx_http_v2_module and the 'http2' option of the 'listen' directive is active in the configuration file ↗
- →Upstream patch available at the nginx mercurial repository — review changeset 1c6b6163c039 for behavioral differences to aid in detection rule development ↗
- →Attack vector is remote; monitor for abnormal memory growth in nginx worker processes receiving HTTP/2 traffic as a sign of exploitation ↗
- ·ngx_http_v2_module is NOT compiled into nginx by default; instances without this module are not vulnerable regardless of nginx version ↗
- ·Red Hat Software Collections rh-nginx18-nginx packages are not affected because they did not include ngx_http_v2_module ↗
- ·Ansible Tower deployments are not affected because the nginx configuration does not enable or use http2 ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-16843: Xcode 13
vendor_apple·2021-09-20·CVSS 7.5
CVE-2018-16843 [HIGH] CVE-2018-16843: Xcode 13
Apple Security Update: About the security content of Xcode 13
Product: Xcode
Version: 13
CVE: CVE-2018-16843
Component: CVE-2018-16843
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)
It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with
Red Hat
nginx: Excessive memory consumption via flaw in HTTP/2 implementation
vendor_redhat·2018-11-06·CVSS 7.5
CVE-2018-16843 [HIGH] CWE-400 nginx: Excessive memory consumption via flaw in HTTP/2 implementation
nginx: Excessive memory consumption via flaw in HTTP/2 implementation
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Statement: This issue did not affect the versions of rh-nginx18-nginx as shipped with Red Hat Software Collections as they did not include the vulnerable module ngx_http_v2_module.
Package: nginx (CloudForms Management Engine 5) - Not affected
Package: openresty (Red Hat 3scale API Management Platform 2) - Not affected
Package: nginx (Red Hat Ansible Tower 3) - Not affected
Package: nginx (Red Hat Enterprise Li
Debian
CVE-2018-16843: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
vendor_debian·2018·CVSS 7.5
CVE-2018-16843 [HIGH] CVE-2018-16843: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolved (fixed in 1.14.1-1)
forky: resolved (fixed in 1.14.1-1)
sid: resolved (fixed in 1.14.1-1)
trixie: resolved (fixed in 1.14.1-1)
GHSA
GHSA-4p62-4q7w-qmcg: nginx before versions 1
ghsa_unreviewed·2022-05-13
CVE-2018-16843 [HIGH] CWE-400 GHSA-4p62-4q7w-qmcg: nginx before versions 1
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
OSV
nginx vulnerabilities
osv·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)
It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with a specially
crafted mp4 file to cause nginx to crash, stop res
OSV
CVE-2018-16843: nginx before versions 1
osv·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] CVE-2018-16843: nginx before versions 1
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation [fedora-all]
bugzilla·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation [fedora-all]
CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation [epel-all]
bugzilla·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation [epel-all]
CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation
bugzilla·2018-10-31·CVSS 7.5
CVE-2018-16843 [HIGH] CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation
CVE-2018-16843 nginx: Excessive memory consumption via flaw in HTTP/2 implementation
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption.
Discussion:
Acknowledgments:
Name: the Nginx project
---
Ansible Tower is not enabling neither using http2 within the nginx configuration file, so it is not affected.
---
Already did some research and discuss with Satoe I. from CloudForms. CFME is not using in any way nginx more than the inclusion from Ansible Tower (not changed or altered configuration or used outside from Tower), and Ansible Tower is not affected, so CloudForms is also not affected; updating the task accordingly.
---
External Reference:
http://mailman.nginx.org/pipermail/nginx-announce/20
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2018/000220.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/105868http://www.securitytracker.com/id/1042038https://access.redhat.com/errata/RHSA-2018:3653https://access.redhat.com/errata/RHSA-2018:3680https://access.redhat.com/errata/RHSA-2018:3681https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843https://support.apple.com/kb/HT212818https://usn.ubuntu.com/3812-1/https://www.debian.org/security/2018/dsa-4335http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2018/000220.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/105868http://www.securitytracker.com/id/1042038https://access.redhat.com/errata/RHSA-2018:3653https://access.redhat.com/errata/RHSA-2018:3680https://access.redhat.com/errata/RHSA-2018:3681https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16843https://support.apple.com/kb/HT212818https://usn.ubuntu.com/3812-1/https://www.debian.org/security/2018/dsa-4335
2018-11-07
Published