Bugzilla – Bug 1115022
VUL-0: CVE-2018-16843: nginx,nginx-1.0: Excessive memory consumption in HTTP/2 implementation
Last modified: 2021-03-19 08:05:15 UTC
rh#1644511 nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. upstream patch: https://hg.nginx.org/nginx/rev/d4448892a294 References: https://bugzilla.redhat.com/show_bug.cgi?id=1644511 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-16843 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-16843.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16843
Hi Artem, my investigation suggests that the following codestream is affected: - SUSE:SLE-15:Update/nginx SLE-11-SP2 is not affected because HTTP/2 is not supported in the version we ship there.
################################ Excessive memory usage in HTTP/2 Severity: low Advisory CVE-2018-16843 Not vulnerable: 1.15.6+, 1.14.1+ Vulnerable: 1.9.5-1.15.5 ################################ Preparing Maintenance Request ...
This is an autogenerated message for OBS integration: This bug (1115022) was mentioned in https://build.opensuse.org/request/show/659058 15.0+42.3+Backports:SLE-12 / nginx
I think everything should be clarified, currently waiting for submission (removing needinfo)
This is an autogenerated message for OBS integration: This bug (1115022) was mentioned in https://build.opensuse.org/request/show/671823 42.3 / nginx
This is an autogenerated message for OBS integration: This bug (1115022) was mentioned in https://build.opensuse.org/request/show/671853 15.0 / nginx
This is an autogenerated message for OBS integration: This bug (1115022) was mentioned in https://build.opensuse.org/request/show/671959 15.0+42.3+Backports:SLE-12 / nginx
SUSE-SU-2019:0334-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1115015,1115022,1115025 CVE References: CVE-2018-16843,CVE-2018-16844,CVE-2018-16845 Sources used: SUSE Linux Enterprise Module for Server Applications 15 (src): nginx-1.14.2-3.3.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src): nginx-1.14.2-3.3.1
openSUSE-SU-2019:0195-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1115015,1115022,1115025 CVE References: CVE-2018-16843,CVE-2018-16844,CVE-2018-16845 Sources used: openSUSE Leap 42.3 (src): nginx-1.14.2-2.7.1 openSUSE Leap 15.0 (src): nginx-1.14.2-lp150.2.4.1
openSUSE-SU-2019:0195-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1115015,1115022,1115025 CVE References: CVE-2018-16843,CVE-2018-16844,CVE-2018-16845 Sources used: openSUSE Leap 42.3 (src): nginx-1.14.2-2.7.1 openSUSE Leap 15.0 (src): nginx-1.14.2-lp150.2.4.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): nginx-1.14.2-16.1
SUSE-SU-2019:2309-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1115015,1115022,1115025,1145579,1145580,1145582 CVE References: CVE-2018-16843,CVE-2018-16844,CVE-2018-16845,CVE-2019-9511,CVE-2019-9513,CVE-2019-9516 Sources used: SUSE Linux Enterprise Module for Server Applications 15-SP1 (src): nginx-1.14.2-6.3.1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (src): nginx-1.14.2-6.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
openSUSE-SU-2019:2120-1: An update that fixes 6 vulnerabilities is now available. Category: security (important) Bug References: 1115015,1115022,1115025,1145579,1145580,1145582 CVE References: CVE-2018-16843,CVE-2018-16844,CVE-2018-16845,CVE-2019-9511,CVE-2019-9513,CVE-2019-9516 Sources used: openSUSE Leap 15.1 (src): nginx-1.14.2-lp151.4.3.1
released