Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2024-28182
HistoryApr 04, 2024 - 3:15 p.m.

CVE-2024-28182

2024-04-0415:15:38
Alpine Linux Development Team
security.alpinelinux.org
7
nghttp2
library
vulnerability
excessive cpu usage
http/2
hpack
mitigation
unix

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7.1

Confidence

High

nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

OSVersionArchitecturePackageVersionFilename
Alpine3.19-mainnoarchnghttp2= 1.58.0-r0UNKNOWN
Alpine3.18-mainnoarchnghttp2= 1.57.0-r0UNKNOWN
Alpine3.17-mainnoarchnghttp2= 1.51.0-r2UNKNOWN

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

7.1

Confidence

High