Security Advisory - Nov. 6, 2018 - CVE-2018-16843, CVE-2018-16844
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
nginx (Ubuntu) |
Fix Released
|
Medium
|
Thomas Ward | ||
Xenial |
Fix Released
|
Medium
|
Unassigned | ||
Bionic |
Fix Released
|
Medium
|
Unassigned | ||
Cosmic |
Fix Released
|
Medium
|
Unassigned | ||
Disco |
Fix Released
|
Medium
|
Thomas Ward |
Bug Description
The following was put out in a security advisory notice over nginx-announce's mailing list today:
http://
Hello!
Two security issues were identified in nginx HTTP/2 implementation,
which might cause excessive memory consumption (CVE-2018-16843)
and CPU usage (CVE-2018-16844).
The issues affect nginx compiled with the ngx_http_v2_module (not
compiled by default) if the "http2" option of the "listen" directive is
used in a configuration file.
The issues affect nginx 1.9.5 - 1.15.5.
The issues are fixed in nginx 1.15.6, 1.14.1.
Thanks to Gal Goldshtein from F5 Networks for initial report of the CPU
usage issue.
-----
Based on the version strings specified, the following Ubuntu versions of nginx are affected:
* Xenial (1.9.15-0ubuntu1, 1.10.3-
* Bionic (1.14.0-0ubuntu1, 1.14.0-0ubuntu1.1)
* Cosmic (1.15.0-0ubuntu1, 1.15.0-0ubuntu2)
* Disco (1.15.0-0ubuntu1, 1.15.0-0ubuntu3)
CVE References
Changed in nginx (Ubuntu Bionic): | |
status: | New → Confirmed |
Changed in nginx (Ubuntu Cosmic): | |
status: | New → Confirmed |
Changed in nginx (Ubuntu Xenial): | |
status: | New → Confirmed |
description: | updated |
Changed in nginx (Ubuntu Xenial): | |
importance: | Undecided → Medium |
Changed in nginx (Ubuntu Bionic): | |
importance: | Undecided → Medium |
Changed in nginx (Ubuntu Cosmic): | |
importance: | Undecided → Medium |
Changed in nginx (Ubuntu Disco): | |
importance: | Undecided → Medium |
assignee: | nobody → Thomas Ward (teward) |
Changed in nginx (Ubuntu Xenial): | |
status: | Confirmed → Fix Released |
Changed in nginx (Ubuntu Bionic): | |
status: | Confirmed → Fix Released |
Changed in nginx (Ubuntu Cosmic): | |
status: | Confirmed → Fix Released |
Changed in nginx (Ubuntu Disco): | |
status: | Confirmed → Fix Committed |
These were addressed in disco in 1.15.6-0ubuntu1, closing. Thanks!