cbcvebase.
CVE-2019-9515
published 2019-08-13

CVE-2019-9515: Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to…

PriorityP359high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
87.81%
99.7th percentile
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

Affected

48 ranges· showing 25
VendorProductVersion rangeFixed in
apachetraffic_server6.0.0 – 6.2.3
apachetraffic_server7.0.0 – 7.1.6
apachetraffic_server8.0.0 – 8.0.3
appleswiftnio1.0.0 – 1.4.0
appleswiftnio_http_2
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianh2o< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
debiantrafficserver< h2o 2.2.5+dfsg2-3 (bookworm)h2o 2.2.5+dfsg2-3 (bookworm)
f5big-ip_local_traffic_manager>= 11.6.1 < 11.6.5.111.6.5.1
f5big-ip_local_traffic_manager>= 12.1.0 < 12.1.5.112.1.5.1
f5big-ip_local_traffic_manager>= 13.1.0 < 13.1.3.213.1.3.2
f5big-ip_local_traffic_manager>= 14.0.0 < 14.0.1.114.0.1.1
f5big-ip_local_traffic_manager>= 14.1.0 < 14.1.2.114.1.2.1
f5big-ip_local_traffic_manager>= 15.0.0 < 15.0.1.115.0.1.1
fedoraprojectfedora
fedoraprojectfedora
h2oh2o>= 0 < 2.2.5+dfsg2-32.2.5+dfsg2-3
h2oh2o>= 0 < 2.2.5+dfsg2-32.2.5+dfsg2-3
mcafeeweb_gateway>= 7.7.2.0 < 7.7.2.247.7.2.24
mcafeeweb_gateway>= 7.8.2.0 < 7.8.2.137.8.2.13
mcafeeweb_gateway>= 8.1.0 < 8.2.08.2.0

Detection & IOCsextracted from sources · hover to see the quote

  • Detect a flood of HTTP/2 SETTINGS frames sent by a client to a server — each empty SETTINGS frame forces one ACK, causing unbounded memory/CPU growth
  • Monitor for rapid, continuous growth in queued SETTINGS ACK frames on HTTP/2 connections, which is the direct mechanism of unbounded memory growth
  • ·nodejs shipped in OpenShift Container Platform 3.9 and 3.10 is NOT affected as it does not contain the vulnerable code
  • ·SwiftNIO HTTP/2 is fixed in version 1.5.0 via improved buffer size management; systems running earlier versions remain vulnerable
  • ·grafana (embedding gRPC) as shipped with Red Hat Ceph Storage 3 is affected due to HTTP/2 support but marked 'Will not fix'

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
ghsa7.5HIGH
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.