Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 583276 (CVE-2016-1546) - <www-servers/apache-2.4.20: mod_http2 denial-of-service by thread starvation (CVE-2016-1546)
Summary: <www-servers/apache-2.4.20: mod_http2 denial-of-service by thread starvation ...
Status: RESOLVED FIXED
Alias: CVE-2016-1546
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://bugzilla.redhat.com/show_bug....
Whiteboard: B3 [glsa cve]
Keywords:
Depends on: CVE-2016-4979
Blocks:
  Show dependency tree
 
Reported: 2016-05-17 10:44 UTC by Agostino Sarubbo
Modified: 2016-10-06 17:26 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2016-05-17 10:44:09 UTC
From ${URL} :

A vulnerability was found in httpd. By manipulating the flow control windows on streams, a client was able to block server threads for long times, causing starvation of worker threads. Connections could still be opened, but no streams where processed for these. 
This issue affected HTTP/2 support in 2.4.17 and 2.4.18.

External references:

http://httpd.apache.org/security/vulnerabilities_24.html


@maintainer(s): since the fixed package is already in the tree, please let us know if it is ready for the stabilization or not.
Comment 1 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2016-05-17 10:57:17 UTC
Arches please test and mark stable the following list of packages:

=app-admin/apache-tools-2.4.20
=www-servers/apache-2.4.20

Target KEYWORDS are:

alpha amd64 arm ~arm64 hppa ia64 ~mips ppc ppc64 ~s390 ~sh sparc x86 ~amd64-fbsd ~sparc-fbsd ~x86-fbsd ~x86-freebsd ~amd64-linux ~x86-linux ~ppc-macos ~x64-macos ~x86-macos ~m68k-mint ~sparc64-solaris ~x64-solaris
Comment 2 Agostino Sarubbo gentoo-dev 2016-05-19 07:41:11 UTC
amd64 stable
Comment 3 Agostino Sarubbo gentoo-dev 2016-05-19 07:42:24 UTC
x86 stable
Comment 4 Markus Meier gentoo-dev 2016-05-19 19:13:30 UTC
arm stable
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2016-05-19 20:05:43 UTC
Stable for HPPA PPC64.
Comment 6 Tobias Klausmann (RETIRED) gentoo-dev 2016-05-21 09:39:28 UTC
Stable on alpha.
Comment 7 Agostino Sarubbo gentoo-dev 2016-07-08 08:19:26 UTC
ppc stable
Comment 8 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-07-08 08:41:22 UTC
Stabilization of higher version happening in bug 588138
Comment 9 GLSAMaker/CVETool Bot gentoo-dev 2016-07-18 02:46:10 UTC
CVE-2016-1546 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-1546):
  The Apache HTTP Server 2.4.17 and 2.4.18, when mod_http2 is enabled, does
  not limit the number of simultaneous stream workers for a single HTTP/2
  connection, which allows remote attackers to cause a denial of service
  (stream-processing outage) via modified flow-control windows.
Comment 10 Aaron Bauman (RETIRED) gentoo-dev 2016-07-18 02:46:47 UTC
Added to existing GLSA.
Comment 11 GLSAMaker/CVETool Bot gentoo-dev 2016-10-06 17:26:22 UTC
This issue was resolved and addressed in
 GLSA 201610-02 at https://security.gentoo.org/glsa/201610-02
by GLSA coordinator Kristian Fiskerstrand (K_F).