vulnerability

SUSE: CVE-2023-44487: SUSE Linux Security Advisory

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
2023-10-10
Added
2023-10-16
Modified
2025-01-28

Description

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Solution(s)

suse-upgrade-abseil-cpp-develsuse-upgrade-corepack14suse-upgrade-corepack16suse-upgrade-corepack18suse-upgrade-go1-20suse-upgrade-go1-20-docsuse-upgrade-go1-20-opensslsuse-upgrade-go1-20-openssl-docsuse-upgrade-go1-20-openssl-racesuse-upgrade-go1-20-racesuse-upgrade-go1-21suse-upgrade-go1-21-docsuse-upgrade-go1-21-opensslsuse-upgrade-go1-21-openssl-docsuse-upgrade-go1-21-openssl-racesuse-upgrade-go1-21-racesuse-upgrade-grpc-develsuse-upgrade-grpc-sourcesuse-upgrade-jetty-annotationssuse-upgrade-jetty-antsuse-upgrade-jetty-cdisuse-upgrade-jetty-clientsuse-upgrade-jetty-continuationsuse-upgrade-jetty-deploysuse-upgrade-jetty-fcgisuse-upgrade-jetty-httpsuse-upgrade-jetty-http-spisuse-upgrade-jetty-iosuse-upgrade-jetty-jaassuse-upgrade-jetty-jmxsuse-upgrade-jetty-jndisuse-upgrade-jetty-jspsuse-upgrade-jetty-minimal-javadocsuse-upgrade-jetty-openidsuse-upgrade-jetty-plussuse-upgrade-jetty-proxysuse-upgrade-jetty-quickstartsuse-upgrade-jetty-rewritesuse-upgrade-jetty-securitysuse-upgrade-jetty-serversuse-upgrade-jetty-servletsuse-upgrade-jetty-servletssuse-upgrade-jetty-startsuse-upgrade-jetty-utilsuse-upgrade-jetty-util-ajaxsuse-upgrade-jetty-webappsuse-upgrade-jetty-xmlsuse-upgrade-kubevirt-container-disksuse-upgrade-kubevirt-manifestssuse-upgrade-kubevirt-testssuse-upgrade-kubevirt-virt-apisuse-upgrade-kubevirt-virt-controllersuse-upgrade-kubevirt-virt-exportproxysuse-upgrade-kubevirt-virt-exportserversuse-upgrade-kubevirt-virt-handlersuse-upgrade-kubevirt-virt-launchersuse-upgrade-kubevirt-virt-operatorsuse-upgrade-kubevirt-virtctlsuse-upgrade-libabsl2308_0_0suse-upgrade-libabsl2308_0_0-32bitsuse-upgrade-libgrpc-1_60suse-upgrade-libgrpc1_60suse-upgrade-libgrpc37suse-upgrade-libnghttp2-14suse-upgrade-libnghttp2-14-32bitsuse-upgrade-libnghttp2-develsuse-upgrade-libnghttp2_asio-develsuse-upgrade-libnghttp2_asio1suse-upgrade-libnghttp2_asio1-32bitsuse-upgrade-libprotobuf-lite25_1_0suse-upgrade-libprotobuf-lite25_1_0-32bitsuse-upgrade-libprotobuf25_1_0suse-upgrade-libprotobuf25_1_0-32bitsuse-upgrade-libprotoc25_1_0suse-upgrade-libprotoc25_1_0-32bitsuse-upgrade-libre2-11suse-upgrade-libre2-11-32bitsuse-upgrade-libupb37suse-upgrade-nettysuse-upgrade-netty-javadocsuse-upgrade-netty-pomssuse-upgrade-netty-tcnativesuse-upgrade-netty-tcnative-javadocsuse-upgrade-nghttp2suse-upgrade-nodejs10suse-upgrade-nodejs10-develsuse-upgrade-nodejs10-docssuse-upgrade-nodejs12suse-upgrade-nodejs12-develsuse-upgrade-nodejs12-docssuse-upgrade-nodejs14suse-upgrade-nodejs14-develsuse-upgrade-nodejs14-docssuse-upgrade-nodejs16suse-upgrade-nodejs16-develsuse-upgrade-nodejs16-docssuse-upgrade-nodejs18suse-upgrade-nodejs18-develsuse-upgrade-nodejs18-docssuse-upgrade-npm10suse-upgrade-npm12suse-upgrade-npm14suse-upgrade-npm16suse-upgrade-npm18suse-upgrade-obs-service-kubevirt_containers_metasuse-upgrade-opencensus-proto-sourcesuse-upgrade-protobuf-develsuse-upgrade-protobuf-javasuse-upgrade-python3-nghttp2suse-upgrade-python311-abseilsuse-upgrade-python311-grpciosuse-upgrade-python311-protobufsuse-upgrade-re2-develsuse-upgrade-tomcatsuse-upgrade-tomcat-admin-webappssuse-upgrade-tomcat-docs-webappsuse-upgrade-tomcat-el-3_0-apisuse-upgrade-tomcat-embedsuse-upgrade-tomcat-javadocsuse-upgrade-tomcat-jsp-2_3-apisuse-upgrade-tomcat-jsvcsuse-upgrade-tomcat-libsuse-upgrade-tomcat-servlet-4_0-apisuse-upgrade-tomcat-webappssuse-upgrade-upb-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.