A flaw was found in HTTP/2. Using PING frames and queuing of response PING ACK frames, a flood attack could occur resulting in unbounded memory growth. The highest threat from this vulnerability is to system availability.
bugzilla.redhat.com/show_bug.cgi?id=1735645
github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.md
groups.google.com/forum/#!topic/golang-announce/65QixT3tcmg
groups.google.com/forum/#!topic/kubernetes-security-announce/wlHLHit1BqA
nodejs.org/en/blog/vulnerability/aug-2019-security-releases/
nvd.nist.gov/vuln/detail/CVE-2019-9512
www.cve.org/CVERecord?id=CVE-2019-9512
www.mail-archive.com/[email protected]/msg06408.html