Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 692112 - <net-libs/nghttp2-1.39.2: Multiple vulnerabilties (CVE-2019-9511,CVE-2019-9513)
Summary: <net-libs/nghttp2-1.39.2: Multiple vulnerabilties (CVE-2019-9511,CVE-2019-9513)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2019-08-14 04:00 UTC by Jeroen Roovers (RETIRED)
Modified: 2019-09-03 19:21 UTC (History)
1 user (show)

See Also:
Package list:
net-libs/nghttp2-1.39.2
Runtime testing required: ---
stable-bot: sanity-check+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jeroen Roovers (RETIRED) gentoo-dev 2019-08-14 04:00:01 UTC
"""
This release fixes CVE-2019-9511 “Data Dribble” and CVE-2019-9513
“Resource Loop” vulnerability in nghttpx and nghttpd. Specially crafted HTTP/2
frames cause Denial of Service by consuming CPU time. Check out
https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
for details. For nghttpx, additionally limiting inbound traffic by --read-rate and --read-burst options is quite effective against this kind of attack.

Fix CVE-2019-9511 and CVE-2019-9513
Add nghttp2_option_set_max_outbound_ack API function
nghttpx: Fix request stall
"""

Oddly, these more or less generic vulnerabilities have been claimed as aliases by bug #692102 already.
Comment 1 Larry the Git Cow gentoo-dev 2019-08-14 05:55:07 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=cf17d7b92109b8841a3cd7418bf098705d668cbb

commit cf17d7b92109b8841a3cd7418bf098705d668cbb
Author:     Lars Wendler <polynomial-c@gentoo.org>
AuthorDate: 2019-08-14 05:54:55 +0000
Commit:     Lars Wendler <polynomial-c@gentoo.org>
CommitDate: 2019-08-14 05:54:55 +0000

    net-libs/nghttp2: Security bump to version 1.39.2
    
    Bug: https://bugs.gentoo.org/692112
    Package-Manager: Portage-2.3.71, Repoman-2.3.17
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 net-libs/nghttp2/Manifest              |  1 +
 net-libs/nghttp2/nghttp2-1.39.2.ebuild | 75 ++++++++++++++++++++++++++++++++++
 2 files changed, 76 insertions(+)
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2019-08-14 15:43:34 UTC
arm64 stable
Comment 3 Larry the Git Cow gentoo-dev 2019-08-14 23:39:22 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=bdcb8b19d690f92b3089f62fcf95e922c4ff0c7b

commit bdcb8b19d690f92b3089f62fcf95e922c4ff0c7b
Author:     Zac Medico <zmedico@gentoo.org>
AuthorDate: 2019-08-14 23:38:09 +0000
Commit:     Zac Medico <zmedico@gentoo.org>
CommitDate: 2019-08-14 23:39:15 +0000

    net-libs/nghttp2: 1.39.2 amd64 stable
    
    Bug: https://bugs.gentoo.org/692112
    Package-Manager: Portage-2.3.71, Repoman-2.3.17
    Signed-off-by: Zac Medico <zmedico@gentoo.org>

 net-libs/nghttp2/nghttp2-1.39.2.ebuild | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)
Comment 4 Rolf Eike Beer archtester 2019-08-15 05:24:23 UTC
sparc stable
Comment 5 Rolf Eike Beer archtester 2019-08-15 18:58:38 UTC
hppa stable
Comment 6 Thomas Deutschmann (RETIRED) gentoo-dev 2019-08-16 22:39:47 UTC
x86 stable
Comment 7 Sergei Trofimovich (RETIRED) gentoo-dev 2019-08-17 20:54:14 UTC
ia64/ppc/ppc64 stable
Comment 8 Agostino Sarubbo gentoo-dev 2019-08-23 10:01:03 UTC
s390 stable
Comment 9 Agostino Sarubbo gentoo-dev 2019-08-23 13:29:03 UTC
alpha stable
Comment 10 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2019-09-01 18:27:53 UTC
arm stable
Comment 11 Aaron Bauman (RETIRED) gentoo-dev 2019-09-02 22:28:57 UTC
@maintainer, please drop vulnerable.
Comment 12 Larry the Git Cow gentoo-dev 2019-09-03 07:56:21 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=1295ce24c304818ce199d5466f7e0732fee2b1fe

commit 1295ce24c304818ce199d5466f7e0732fee2b1fe
Author:     Lars Wendler <polynomial-c@gentoo.org>
AuthorDate: 2019-09-03 07:49:27 +0000
Commit:     Lars Wendler <polynomial-c@gentoo.org>
CommitDate: 2019-09-03 07:49:27 +0000

    net-libs/nghttp2: Security cleanup
    
    Bug: https://bugs.gentoo.org/692112
    Package-Manager: Portage-2.3.75, Repoman-2.3.17
    Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>

 net-libs/nghttp2/Manifest              |  1 -
 net-libs/nghttp2/nghttp2-1.39.1.ebuild | 75 ----------------------------------
 2 files changed, 76 deletions(-)
Comment 13 Aaron Bauman (RETIRED) gentoo-dev 2019-09-03 19:21:50 UTC
(In reply to Larry the Git Cow from comment #12)
> The bug has been referenced in the following commit(s):
> 
> https://gitweb.gentoo.org/repo/gentoo.git/commit/
> ?id=1295ce24c304818ce199d5466f7e0732fee2b1fe
> 
> commit 1295ce24c304818ce199d5466f7e0732fee2b1fe
> Author:     Lars Wendler <polynomial-c@gentoo.org>
> AuthorDate: 2019-09-03 07:49:27 +0000
> Commit:     Lars Wendler <polynomial-c@gentoo.org>
> CommitDate: 2019-09-03 07:49:27 +0000
> 
>     net-libs/nghttp2: Security cleanup
>     
>     Bug: https://bugs.gentoo.org/692112
>     Package-Manager: Portage-2.3.75, Repoman-2.3.17
>     Signed-off-by: Lars Wendler <polynomial-c@gentoo.org>
> 
>  net-libs/nghttp2/Manifest              |  1 -
>  net-libs/nghttp2/nghttp2-1.39.1.ebuild | 75
> ----------------------------------
>  2 files changed, 76 deletions(-)

Danke!