VDB
RHSA-2020:3196
RHSA-2020:3196
PUBLISHED
CVSS 7.5 HIGH
A flaw was found in HTTP/2. Using PING frames and queuing of response PING ACK frames, a flood attack could occur resulting in unbounded memory growth. The highest threat from this vulnerability is to system availability.
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Decision Manager 7 |
Timeline
- Jul 29, 2020 CVE Published
- Apr 28, 2026 Distribution Patch
- Apr 28, 2026 Distribution Patch
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
- Apr 28, 2026 Security Advisory
References
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=rhdm&version=7.8.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1735645 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1735749 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1796225 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1798524 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1801149 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1815470 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1816216 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1816330 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1819208 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1821304 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1821311 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1821315 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=1826798 issue
- https://access.redhat.com/security/cve/CVE-2019-9512 advisory
- https://groups.google.com/forum/#!topic/golang-announce/65QixT3tcmg advisory
- https://access.redhat.com/security/cve/CVE-2019-9514 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-9514 advisory
- https://access.redhat.com/security/cve/CVE-2019-9515 advisory
…and 119 more