CVE-2024-28182
MEDIUM
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
Record summary
CVE-2024-28182 has a selected CVSS score of 5.3 (medium); EIP currently links 1 repository PoC.
Description
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 4, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
nghttp2Browse nghttp2 / nghttp2Default status: unknown | CVE List | Before 1.61.0 | affected |
| < 1.61.0 | affected |
Proofs of concept
1Repository PoCs
GitHublockness-Ko/CVE-2024-27316Repository PoCby lockness-KoStars: 18Not analyzed6 files
References
10openwall.com
http://www.openwall.com/lists/oss-security/2024/04/03/16 github.com
https://github.com/nghttp2/nghttp2/commit/00201ecd8f982da3b67d4f6868af72a1b03b14e0 github.com
https://github.com/nghttp2/nghttp2/commit/d71a4668c6bead55805d18810d633fbb98315af9 github.comConfirmation
https://github.com/nghttp2/nghttp2/security/advisories/GHSA-x6x3-gv8h-m57q lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/04/msg00026.html lists.debian.org
https://lists.debian.org/debian-lts-announce/2024/09/msg00041.html lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AGOME6ZXJG7664IPQNVE3DL67E3YP3HY lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J6ZMXUGB66VAXDW5J6QSTHM5ET25FGSA lists.fedoraproject.org
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PXJO2EASHM2OQQLGVDY5ZSO7UVDVHTDK kb.cert.org
https://www.kb.cert.org/vuls/id/421644