CVE-2018-16844
published 2018-11-07CVE-2018-16844: nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
12.40%
95.8th percentile
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | xcode | < 13.0 | 13.0 |
| apple | xcode | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | nginx | < nginx 1.14.1-1 (bookworm) | nginx 1.14.1-1 (bookworm) |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.14.1-1 | 1.14.1-1 |
| f5 | nginx | >= 0 < 1.4.6-1ubuntu3.9 | 1.4.6-1ubuntu3.9 |
| f5 | nginx | >= 0 < 1.10.3-0ubuntu0.16.04.3 | 1.10.3-0ubuntu0.16.04.3 |
| f5 | nginx | >= 0 < 1.14.0-0ubuntu1.2 | 1.14.0-0ubuntu1.2 |
| f5 | nginx | >= 1.15.0 < 1.15.6 | 1.15.6 |
| f5 | nginx | >= 1.9.5 < 1.14.1 | 1.14.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Apple
CVE-2018-16844: Xcode 13
vendor_apple·2021-09-20·CVSS 7.5
CVE-2018-16844 [HIGH] CVE-2018-16844: Xcode 13
Apple Security Update: About the security content of Xcode 13
Product: Xcode
Version: 13
CVE: CVE-2018-16844
Component: CVE-2018-16844
Ubuntu
nginx vulnerabilities
vendor_ubuntu·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] nginx vulnerabilities
Title: nginx vulnerabilities
Summary: Several security issues were fixed in nginx.
It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)
It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with
Red Hat
nginx: Excessive CPU usage via flaw in HTTP/2 implementation
vendor_redhat·2018-11-06·CVSS 7.5
CVE-2018-16844 [HIGH] CWE-400 nginx: Excessive CPU usage via flaw in HTTP/2 implementation
nginx: Excessive CPU usage via flaw in HTTP/2 implementation
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Statement: This issue did not affect the versions of rh-nginx18-nginx as shipped with Red Hat Software Collections as they did not include the vulnerable module ngx_http_v2_module.
Package: nginx (CloudForms Management Engine 5) - Not affected
Package: nginx (Red Hat Ansible Tower 3) - Not affected
Package: nginx (Red Hat Enterprise Linux 8) - Not affected
Package: rh-nginx110-nginx (Red Hat Software Collections) - Will not fix
Debian
CVE-2018-16844: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
vendor_debian·2018·CVSS 7.5
CVE-2018-16844 [HIGH] CVE-2018-16844: nginx - nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementatio...
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
Scope: local
bookworm: resolved (fixed in 1.14.1-1)
bullseye: resolved (fixed in 1.14.1-1)
forky: resolved (fixed in 1.14.1-1)
sid: resolved (fixed in 1.14.1-1)
trixie: resolved (fixed in 1.14.1-1)
GHSA
GHSA-4576-cf38-77f2: nginx before versions 1
ghsa_unreviewed·2022-05-13
CVE-2018-16844 [HIGH] CWE-400 GHSA-4576-cf38-77f2: nginx before versions 1
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
OSV
nginx vulnerabilities
osv·2018-11-07·CVSS 7.5
CVE-2018-16843 [HIGH] nginx vulnerabilities
nginx vulnerabilities
It was discovered that nginx incorrectly handled the HTTP/2 implementation.
A remote attacker could possibly use this issue to cause excessive memory
consumption, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10. (CVE-2018-16843)
Gal Goldshtein discovered that nginx incorrectly handled the HTTP/2
implementation. A remote attacker could possibly use this issue to cause
excessive CPU usage, leading to a denial of service. This issue only
affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 18.10.
(CVE-2018-16844)
It was discovered that nginx incorrectly handled the ngx_http_mp4_module
module. A remote attacker could possibly use this issue with a specially
crafted mp4 file to cause nginx to crash, stop res
OSV
CVE-2018-16844: nginx before versions 1
osv·2018-11-07·CVSS 7.5
CVE-2018-16844 [HIGH] CVE-2018-16844: nginx before versions 1
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation [epel-all]
bugzilla·2018-11-07·CVSS 7.5
CVE-2018-16844 [HIGH] CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation [epel-all]
CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation [fedora-all]
bugzilla·2018-11-07·CVSS 7.5
CVE-2018-16844 [HIGH] CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation [fedora-all]
CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation
bugzilla·2018-10-31·CVSS 7.5
CVE-2018-16844 [HIGH] CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation
CVE-2018-16844 nginx: Excessive CPU usage via flaw in HTTP/2 implementation
nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage.
Discussion:
Acknowledgments:
Name: the Nginx project
---
Ansible Tower is not enabling neither using http2 within the nginx configuration file, so it is not affected.
---
Already did some research and discuss with Satoe I. from CloudForms. CFME is not using in any way nginx more than the inclusion from Ansible Tower (not changed or altered configuration or used outside from Tower), and Ansible Tower is not affected, so CloudForms is also not affected; updating the task accordingly.
---
External Reference:
http://mailman.nginx.org/pipermail/nginx-announce/2018/000220.html
--
http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2018/000220.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/105868http://www.securitytracker.com/id/1042038https://access.redhat.com/errata/RHSA-2018:3680https://access.redhat.com/errata/RHSA-2018:3681https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16844https://support.apple.com/kb/HT212818https://usn.ubuntu.com/3812-1/https://www.debian.org/security/2018/dsa-4335http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00035.htmlhttp://mailman.nginx.org/pipermail/nginx-announce/2018/000220.htmlhttp://seclists.org/fulldisclosure/2021/Sep/36http://www.securityfocus.com/bid/105868http://www.securitytracker.com/id/1042038https://access.redhat.com/errata/RHSA-2018:3680https://access.redhat.com/errata/RHSA-2018:3681https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16844https://support.apple.com/kb/HT212818https://usn.ubuntu.com/3812-1/https://www.debian.org/security/2018/dsa-4335
2018-11-07
Published