{"id":"MGASA-2019-0291","summary":"Updated nghttp2 packages fix security vulnerabilities","details":"The updated packages fix security vulnerabilities:\n\nSome HTTP/2 implementations are vulnerable to window size manipulation\nand stream prioritization manipulation, potentially leading to a denial\nof service. The attacker requests a large amount of data from a specified\nresource over multiple streams. They manipulate window size and stream\npriority to force the server to queue the data in 1-byte chunks. Depending\non how efficiently this data is queued, this can consume excess CPU,\nmemory, or both. (CVE-2019-9511)\n\nSome HTTP/2 implementations are vulnerable to resource loops, potentially\nleading to a denial of service. The attacker creates multiple request\nstreams and continually shuffles the priority of the streams in a way that\ncauses substantial churn to the priority tree. This can consume excess CPU.\n(CVE-2019-9513)\n","modified":"2026-04-16T04:43:43.198891399Z","published":"2019-09-28T01:05:09Z","upstream":["CVE-2019-9511","CVE-2019-9513"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2019-0291.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=25424"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:2692"}],"affected":[{"package":{"name":"nghttp2","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/nghttp2?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9.2-1.1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0291.json"}},{"package":{"name":"nghttp2","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/nghttp2?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.38.0-1.1.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2019-0291.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}