HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2019-9515

CVSS 7.5v3.1pub. 2019-08-13upd. 2025-01-14

Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a ping. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Apache Traffic Server

    APP
    Apache
    7.0.0 – 7.1.68.0.0 – 8.0.36.0.0 – 6.2.3
  • Apple Mac Os X

    OS
    Apple
    ≥ 10.12
  • Apple Swiftnio

    APP
    Apple
    1.0.0 – 1.4.0
  • Canonical Ubuntu

    OS
    Canonical
    16.0418.0419.04≥ 14.04
  • Debian

    OS
    Debian
    10.09.0
  • F5 Big Ip Local Traffic Manager

    APP
    F5
    11.6.1 – 11.6.5.1 (excl.)12.1.0 – 12.1.5.1 (excl.)13.1.0 – 13.1.3.2 (excl.)14.0.0 – 14.0.1.1 (excl.)14.1.0 – 14.1.2.1 (excl.)15.0.0 – 15.0.1.1 (excl.)
  • Fedora Project Fedora

    OS
    Fedoraproject
    2930
  • Mcafee Web Gateway

    APP
    Mcafee
    7.7.2.0 – 7.7.2.24 (excl.)7.8.2.0 – 7.8.2.13 (excl.)8.1.0 – 8.2.0 (excl.)
  • Node.js

    APP
    Nodejs
    8.0.0 – 8.8.112.0.0 – 12.8.1 (excl.)10.13.0 – 10.16.3 (excl.)10.0.0 – 10.12.08.9.0 – 8.16.1 (excl.)
  • Opensuse Leap

    OS
    Opensuse
    15.015.1
  • Oracle Graalvm

    APP
    Oracle
    19.2.0
  • Red Hat Enterprise Linux

    OS
    Redhat
    8.0
  • Red Hat Jboss Core Services

    APP
    Redhat
    1.0
  • Red Hat Jboss Enterprise Application Platform

    APP
    Redhat
    7.2.07.3.0
  • Red Hat OpenShift Container Platform

    APP
    Redhat
    4.1
  • Red Hat Openshift Service Mesh

    APP
    Redhat
    1.0
  • Red Hat Openstack

    APP
    Redhat
    14
  • Red Hat Quay

    APP
    Redhat
    3.0.0
  • Red Hat Single Sign On

    APP
    Redhat
    7.3
  • Red Hat Software Collections

    APP
    Redhat
    1.0
  • Synology Diskstation Manager

    OS
    Synology
    6.2
  • Synology Skynas

    APP
    Synology
    all versions
  • Synology Vs960hd

    HW
    Synology
    all versions
  • Synology Vs960hd Firmware

    OS
    Synology
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2026-24061CRITICAL9.8⚠ KEVPL ✓same product

GNU Inetutils telnetd: ominięcie uwierzytelnienia przez zmienną USER

CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product

Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)

CVE-2025-49113CRITICAL9.9⚠ KEVPL ✓same product

RCE przez deserializację PHP w Roundcube Webmail (parametr _from)

CVE-2025-32433CRITICAL10.0⚠ KEVPL ✓same product

Erlang/OTP SSH — nieuwierzytelniony RCE (CVSS 10.0)

CVE-2025-24201CRITICAL10.0⚠ KEVPL ✓same product

Apple WebKit: out-of-bounds write umożliwiający ucieczkę z sandbox przeglądarki