VDB
BDU%3A2023-06559
BDU%3A2023-06559
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость реализации протокола HTTP/2, связанная с возможностью формирования потока запросов в рамках уже установленного сетевого соединения, без открытия новых сетевых соединений и без подтверждения получения пакетов, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft Corp, ООО «РусБИТех-Астра», Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», АО «ИВК», Canonical Ltd., АО «НТЦ ИТ РОСА», Fedora Project, Willy Terreau, The Go Project, Google Inc, Eclipse Foundation, Apache Software Foundation, NGINX Inc., АО "НППКТ", Axiom JDK, ООО «Открытая мобильная платформа», ООО "Веб-Сервер" | Windows 10 1607, Windows Server 2016, Windows Server 2016 (Server Core installation), Windows 10 1809, Windows Server 2019, Windows Server 2019 (Server Core installation), Astra Linux Special Edition (запись в едином реестре российских программ №369), SUSE Linux Enterprise Server for SAP Applications, OpenSUSE Leap, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Web Scripting, Red Hat Enterprise Linux, SUSE Linux Enterprise Software Development Kit, OpenShift Container Platform, H2O, Debian GNU/Linux, openSUSE Tumbleweed, SUSE CaaS Platform, Openshift Service Mesh, Windows Server 2022, Windows Server 2022 (Server Core installation), РЕД ОС (запись в едином реестре российских программ №3751), Windows 10 21H2, SUSE Manager Proxy, SUSE Manager Server, ASP.NET Core, SUSE Linux Enterprise Micro, Альт 8 СП (запись в едином реестре российских программ №4305), Suse Linux Enterprise Desktop, SUSE Manager Retail Branch Server, Ubuntu, Red Hat OpenStack Platform, SUSE Linux Enterprise Module for Basesystem, SUSE Linux Enterprise Module for Development Tools, Microsoft Visual Studio 2022, Windows 11 22H2, Windows 10 22H2, openSUSE Leap Micro, .NET, Windows 11 21H2, Red Hat Ceph Storage, РОСА Кобальт (запись в едином реестре российских программ №1999), Fedora, SUSE Package Hub, SUSE Linux Enterprise Module for Public Cloud, ROSA Virtualization (запись в едином реестре российских программ №5091), РОСА ХРОМ (запись в едином реестре российских программ №1607), SUSE Linux Enterprise Module for Package Hub, Envoy, Cryostat, HAProxy, Go, gRPC, Jetty, netty, nghttp2, Tomcat, Traffic Server, NGINX Plus, NGINX Open Source, NGINX Ingress Controller, АЛЬТ СП 10, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), SUSE Liberty Linux, SUSE Linux Enterprise Module for Containers, SUSE Linux Enterprise Module for Server Applications, SUSE Linux Enterprise Module for Python 3, ROSA Virtualization 3.0 (запись в едином реестре российских программ №21308), Libercat Certified (запись в едином реестре российских программ №22725; 9208), SUSE Linux Micro, Fedora EPEL, ОС Аврора (запись в едином реестре российских программ №1543), Angie, Angie PRO |
Timeline
- Oct 11, 2023 CVE Published
- Dec 18, 2025 CVE Updated
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Security Advisory
- Mar 19, 2026 Security Advisory
References
- https://security-tracker.debian.org/tracker/CVE-2023-44487 url
- https://access.redhat.com/security/cve/CVE-2023-44487 url
- https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/ url
- https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html url
- https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo url
- https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf url
- https://github.com/h2o/h2o/commit/28fe15117b909588bf14269a0e1c6ec4548579fe url
- https://github.com/grpc/grpc-go/pull/6703 url
- https://github.com/nghttp2/nghttp2/pull/1961 url
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M12 url
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.81 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.9/ url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2024-0416SE47 url
- https://github.com/micrictor/http2-rst-stream url
- https://wiki.astralinux.ru/astra-linux-se16-bulletin-20241017SE16 url
- https://abf.rosa.ru/advisories/ROSA-SA-2024-2418 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2740 url
- https://abf.rosa.ru/advisories/ROSA-SA-2025-2895 url
- https://cve.omp.ru/bb27514 url
- https://www.suse.com/security/cve/CVE-2023-44487.html url
…and 24 more