PT-2019-3017 · Google+9 · Golang.Org/X/Net/Http2+11

Jonathan Looney

·

Published

2019-08-13

·

Updated

2026-05-18

·

CVE-2019-9512

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions HTTP/2 implementations (affected versions not specified) golang.org/x/net/http2 (affected versions not specified) Arista EOS (with TerminAttr and OpenConfig enabled) Arista CloudVision Portal (ingest component in the CVP Backend) Arista Wi-Fi software (Access Points with OpenConfig interface enabled)
Description Some HTTP/2 implementations are vulnerable to ping floods and reset floods, potentially leading to a denial of service. An attacker can send continual pings or invalid requests to an HTTP/2 peer, causing the peer to build an internal queue of responses or RST STREAM frames. This can consume excess CPU, memory, or both, potentially leading to a crash. The vulnerability can be exploited by a remote attacker, allowing them to cause a denial of service.
Recommendations For HTTP/2 implementations, consider disabling the ping flood and reset flood features until a patch is available. For golang.org/x/net/http2, restrict access to the affected package until a patch is available. For Arista EOS, disable TerminAttr and OpenConfig services until a patch is available. For Arista CloudVision Portal, restrict access to the ingest component in the CVP Backend until a patch is available. For Arista Wi-Fi software, disable the OpenConfig interface on Access Points until a patch is available. As a temporary workaround, consider restricting the amount of memory and CPU allocated to the affected services to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2019:2925
ALSA-2019:4269
ALSA-2019:4273
ALT-PU-2019-2494
ALT-PU-2019-2495
ALT-PU-2019-2525
ALT-PU-2019-2564
ALT-PU-2019-2792
ALT-PU-2019-2794
ALT-PU-2019-3050
ALT-PU-2020-2195
AZL-38449
BDU:2019-02995
BDU:2019-02996
BDU:2020-03827
CESA-2019_2726
CESA-2019_2925
CESA-2019_4269
CESA-2019_4273
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2019-9512
DLA-2485-1
DSA-4503-1
DSA-4508-1
DSA-4520-1
GHSA-39QC-96H7-956F
GHSA-HGR8-6H9X-F7Q9
GO-2022-0536
MGASA-2019-0251
MGASA-2020-0372
MGASA-2020-0468
OPENSUSE-SU-2019:2000-1
OPENSUSE-SU-2019:2056-1
OPENSUSE-SU-2019:2072-1
OPENSUSE-SU-2019:2085-1
OPENSUSE-SU-2019:2114-1
OPENSUSE-SU-2019:2115-1
OPENSUSE-SU-2019:2130-1
OPENSUSE-SU-2019_2000-1
OPENSUSE-SU-2019_2056-1
OPENSUSE-SU-2019_2072-1
OPENSUSE-SU-2019_2085-1
OPENSUSE-SU-2019_2114-1
OPENSUSE-SU-2019_2115-1
OPENSUSE-SU-2019_2130-1
OPENSUSE-SU-2024:10804-1
OPENSUSE-SU-2024:10805-1
OPENSUSE-SU-2024:10901-1
OPENSUSE-SU-2024:11098-1
OPENSUSE-SU-2024:11212-1
RHSA-2019:2661
RHSA-2019:2682
RHSA-2019:2690
RHSA-2019:2726
RHSA-2019:2769
RHSA-2019:2796
RHSA-2019:2817
RHSA-2019:2925
RHSA-2019:2939
RHSA-2019:2955
RHSA-2019:3131
RHSA-2019:3245
RHSA-2019:3265
RHSA-2019:3906
RHSA-2019:4018
RHSA-2019:4019
RHSA-2019:4020
RHSA-2019:4040
RHSA-2019:4041
RHSA-2019:4042
RHSA-2019:4269
RHSA-2019:4273
RHSA-2019_2726
RHSA-2019_2925
RHSA-2019_4269
RHSA-2019_4273
RHSA-2020:0406
RHSA-2024:5856
RLSA-2019:2925
RLSA-2019:4269
RLSA-2019:4273
SUSE-SU-2019:14246-1
SUSE-SU-2019:2213-1
SUSE-SU-2019:2214-1
SUSE-SU-2019:2254-1
SUSE-SU-2019:2259-1
SUSE-SU-2019:2260-1
SUSE-SU-2019_14246-1
SUSE-SU-2020:0059-1
USN-4308-1
USN-4866-1

Affected Products

Alt Linux
Almalinux
Arista Cloudvision Portal
Arista Eos
Arista Wi-Fi
Centos
Red Hat
Rocky Linux
Suse
Ubuntu
Windows
Golang.Org/X/Net/Http2