CVE-2023-39325

A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. With the fix applied, HTTP/2 servers now bound the number of simultaneously executing handler goroutines to the stream concurrency limit (MaxConcurrentStreams). New requests arriving when at the limit (which can only happen after the client has reset an existing, in-flight request) will be queued until a handler exits. If the request queue grows too large, the server will terminate the connection. This issue is also fixed in golang.org/x/net/http2 for users manually configuring HTTP/2. The default stream concurrency limit is 250 streams (requests) per HTTP/2 connection. This value may be adjusted using the golang.org/x/net/http2 package; see the Server.MaxConcurrentStreams setting and the ConfigureServer function.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
Affected Products (NVD)
VendorProductVersion
golanggo
1.20.0 ≤
𝑥
< 1.20.10
golanggo
1.21.0 ≤
𝑥
< 1.21.3
golanghttp2
𝑥
< 0.17.0
netappastra_trident
-
netappastra_trident_autosupport
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
golang-1.15
bookworm
no-dsa
bullseye
vulnerable
buster
postponed
golang-1.19
bookworm
vulnerable
bullseye
no-dsa
buster
postponed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
golang-1.10
bionic
needs-triage
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
needs-triage
golang-1.13
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
needs-triage
golang-1.14
bionic
dne
focal
needs-triage
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
golang-1.16
bionic
needs-triage
focal
needs-triage
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
golang-1.17
bionic
dne
focal
dne
jammy
Fixed 1.17.13-3ubuntu1.2
released
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
golang-1.18
bionic
Fixed 1.18.1-1ubuntu1~18.04.4+esm1
released
focal
Fixed 1.18.1-1ubuntu1~20.04.3
released
jammy
Fixed 1.18.1-1ubuntu1.2
released
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
Fixed 1.18.1-1ubuntu1~16.04.6+esm1
released
golang-1.19
bionic
ignored
focal
dne
jammy
dne
lunar
ignored
mantic
dne
noble
dne
oracular
dne
trusty
ignored
xenial
ignored
golang-1.20
bionic
ignored
focal
Fixed 1.20.3-1ubuntu0.1~20.04.1
released
jammy
Fixed 1.20.3-1ubuntu0.1~22.04.1
released
lunar
Fixed 1.20.3-1ubuntu0.2
released
mantic
Fixed 1.20.8-1ubuntu0.23.10.1
released
noble
dne
oracular
dne
trusty
ignored
xenial
ignored
golang-1.21
bionic
ignored
focal
Fixed 1.21.1-1~ubuntu20.04.2
released
jammy
Fixed 1.21.1-1~ubuntu22.04.2
released
lunar
Fixed 1.21.1-1~ubuntu23.04.2
released
mantic
Fixed 1.21.1-1ubuntu0.23.10.1
released
noble
not-affected
oracular
dne
trusty
ignored
xenial
ignored
golang-1.6
bionic
dne
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
needs-triage
golang-1.8
bionic
needs-triage
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
golang-1.9
bionic
needs-triage
focal
dne
jammy
dne
lunar
dne
mantic
dne
noble
dne
oracular
dne
trusty
dne
xenial
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
containerized-data-importer-manifests
suse enterprise sap 15 SP7
1.64.0-150700.9.11.1
fixed
suse enterprise server 15 SP7
1.64.0-150700.9.11.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
golang
RHEL 9
0:1.19.13-1.el9_2
fixed
golang-bin
RHEL 9
0:1.19.13-1.el9_2
fixed
golang-docs
RHEL 9
0:1.19.13-1.el9_2
fixed
golang-misc
RHEL 9
0:1.19.13-1.el9_2
fixed
golang-race
RHEL 9
0:1.19.13-1.el9_2
fixed
golang-src
RHEL 9
0:1.19.13-1.el9_2
fixed
golang-tests
RHEL 9
0:1.19.13-1.el9_2
fixed
grafana
RHEL 9
0:9.0.9-4.el9_2
fixed
rhc-worker-script
RHEL 7
0:0.5-1.el7_9
fixed
toolbox
RHEL 9
0:0.0.99.3-10.el9_2
fixed
toolbox-tests
RHEL 9
0:0.0.99.3-10.el9_2
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
amazon-cloudwatch-agent
Amazon Linux 2
0:1.300032.3-1.amzn2
fixed
Amazon Linux 2023
0:1.300032.3-1.amzn2023
fixed
amazon-ssm-agent
Amazon Linux 1
0:3.2.2222.0-1.amzn1
fixed
Amazon Linux 2
0:3.2.2222.0-1.amzn2
fixed
Amazon Linux 2023
0:3.2.2222.0-1.amzn2023
fixed
amazon-ssm-agent-debuginfo
Amazon Linux 1
0:3.2.2222.0-1.amzn1
fixed
Amazon Linux 2
0:3.2.2222.0-1.amzn2
fixed
Amazon Linux 2023
0:3.2.2222.0-1.amzn2023
fixed
amazon-ssm-agent-debugsource
Amazon Linux 2023
0:3.2.2222.0-1.amzn2023
fixed
cni-plugins
Amazon Linux 2
0:1.2.0-1.amzn2.0.4
fixed
Amazon Linux 2023
0:1.2.0-1.amzn2023.0.3
fixed
cni-plugins-debuginfo
Amazon Linux 2
0:1.2.0-1.amzn2.0.4
fixed
Amazon Linux 2023
0:1.2.0-1.amzn2023.0.3
fixed
cni-plugins-debugsource
Amazon Linux 2023
0:1.2.0-1.amzn2023.0.3
fixed
cri-tools
Amazon Linux 2
0:1.26.1-1.amzn2.0.3
fixed
cri-tools-debuginfo
Amazon Linux 2
0:1.26.1-1.amzn2.0.3
fixed
docker
Amazon Linux 2023
0:24.0.5-1.amzn2023.0.2
fixed
docker-debuginfo
Amazon Linux 2023
0:24.0.5-1.amzn2023.0.2
fixed
docker-debugsource
Amazon Linux 2023
0:24.0.5-1.amzn2023.0.2
fixed
ecs-init
Amazon Linux 2023
0:1.77.0-1.amzn2023
fixed
golang
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golang-bin
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golang-docs
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golang-misc
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golang-shared
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golang-src
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golang-tests
Amazon Linux 1
0:1.20.10-1.48.amzn1
fixed
Amazon Linux 2
0:1.20.10-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.20.10-1.amzn2023.0.1
fixed
golist
Amazon Linux 2
0:0.10.1-10.amzn2.0.4
fixed
golist-debuginfo
Amazon Linux 2
0:0.10.1-10.amzn2.0.4
fixed
nerdctl
Amazon Linux 2
0:1.6.2-1.amzn2.0.2
fixed
nerdctl-debuginfo
Amazon Linux 2
0:1.6.2-1.amzn2.0.2
fixed
oci-add-hooks
Amazon Linux 2023
0:0-0.1.20200504git268e3bb.amzn2023.0.2
fixed
oci-add-hooks-debuginfo
Amazon Linux 2023
0:0-0.1.20200504git268e3bb.amzn2023.0.2
fixed
oci-add-hooks-debugsource
Amazon Linux 2023
0:0-0.1.20200504git268e3bb.amzn2023.0.2
fixed
runc
Amazon Linux 2023
0:1.1.7-1.amzn2023.0.3
fixed
runc-debuginfo
Amazon Linux 2023
0:1.1.7-1.amzn2023.0.3
fixed
runc-debugsource
Amazon Linux 2023
0:1.1.7-1.amzn2023.0.3
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
application-gateway-kubernetes-ingress
Azure Linux 3.0
0:1.7.7-1.azl3
fixed
blobfuse2
Azure Linux 3.0
0:2.3.0-1.azl3
fixed
CBL-Mariner 2.0
0:2.1.1-1.cm2
fixed
cert-manager
Azure Linux 3.0
0:1.11.2-5.azl3
fixed
CBL-Mariner 2.0
0:1.11.2-5.cm2
fixed
cf-cli
Azure Linux 3.0
0:8.7.3-2.azl3
fixed
containerized-data-importer
Azure Linux 3.0
0:1.57.0-8.azl3
fixed
coredns
Azure Linux 3.0
0:1.9.3-9.azl3
fixed
CBL-Mariner 2.0
0:1.9.3-9.cm2
fixed
cri-tools
CBL-Mariner 2.0
0:1.28.0-2.cm2
fixed
etcd
Azure Linux 3.0
0:3.5.6-11.azl3
fixed
CBL-Mariner 2.0
0:3.5.6-11.cm2
fixed
git-lfs
Azure Linux 3.0
0:3.6.1-1.azl3
fixed
CBL-Mariner 2.0
0:3.5.1-1.cm2
fixed
golang
Azure Linux 3.0
0:0.0.0.azl3
fixed
CBL-Mariner 2.0
0:1.19.0.cm2
fixed
jx
Azure Linux 3.0
0:3.10.182-1.azl3
fixed
kata-containers
Azure Linux 3.0
0:3.2.0.azl4-1.azl3
fixed
CBL-Mariner 2.0
0:3.2.0.azl2-1.cm2
fixed
kata-containers-cc
Azure Linux 3.0
0:3.2.0.azl4-1.azl3
fixed
CBL-Mariner 2.0
0:3.2.0.azl2-1.cm2
fixed
kube-vip-cloud-provider
Azure Linux 3.0
0:0.0.10-1.azl3
fixed
kured
CBL-Mariner 2.0
0:1.9.1-14.cm2
fixed
local-path-provisioner
Azure Linux 3.0
0:0.0.24-3.azl3
fixed
moby-compose
CBL-Mariner 2.0
0:2.17.2-5.cm2
fixed
moby-containerd
CBL-Mariner 2.0
0:1.6.22-2.cm2
fixed
moby-containerd-cc
Azure Linux 3.0
0:1.7.1-5.azl3
fixed
CBL-Mariner 2.0
0:1.7.1-5.cm2
fixed
multus
Azure Linux 3.0
0:4.0.2-3.azl3
fixed
CBL-Mariner 2.0
0:3.8-12.cm2
fixed
opa
Azure Linux 3.0
0:0.50.2-6.azl3
fixed
CBL-Mariner 2.0
0:0.50.2-6.cm2
fixed
packer
Azure Linux 3.0
0:1.9.5-1.azl3
fixed
CBL-Mariner 2.0
0:1.8.7-2.cm2
fixed
prometheus
CBL-Mariner 2.0
0:2.37.9-2.cm2
fixed
prometheus-adapter
Azure Linux 3.0
0:0.12.0-1.azl3
fixed
skopeo
CBL-Mariner 2.0
0:1.12.0-4.cm2
fixed
telegraf
Azure Linux 3.0
0:1.27.3-3.azl3
fixed
CBL-Mariner 2.0
0:1.27.3-3.cm2
fixed
vitess
Azure Linux 3.0
0:16.0.2-5.azl3
fixed
CBL-Mariner 2.0
0:16.0.2-5.cm2
fixed
References