CVE-2023-44487

HTTP/2 Rapid Reset: a protocol flaw that turned into the largest attacks ever recorded

Not a memory bug. HTTP/2 lets a client open a request and cancel it immediately, and the cancellation costs the client nothing while costing the server real work. Doing that in a loop produced denial-of-service attacks an order of magnitude larger than anything seen before.

nginx and ApacheIn CISA’s Known Exploited catalogue since 2023-10-10EPSS 100.0% chance of an attempt in 30 daysCVSS 7.5CWE-400CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A fixed package version is available on 3 of the releases below. 1 has an advisory with no fix released. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

A client streams RST_STREAM frames to cancel requests as fast as it can create them. The server keeps allocating and tearing down request state while the connection limit is never reached, because cancelled streams do not count against it.

What an attacker gets: Denial of service, at a scale that made it notable. No data disclosure and no code execution.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • HTTP/2 has to be enabled and reachable. A server behind a reverse proxy or a CDN that terminates HTTP/2 is protected by whatever that layer does, not by its own version.
  • The fixes are rate limits and accounting changes rather than a single corrected line, so different servers addressed it differently and on different dates.
  • This is the clearest case on this site of a CVE being about a protocol rather than a package. The table below shows nginx carrying advisories and Apache HTTP Server carrying none for these releases, which is a real difference and not a gap.

Check your own server

Read-only, changes nothing
ss -lntp | grep -E ':(80|443)' && (nginx -V 2>&1 | grep -o with-http_v2_module; grep -rn 'http2' /etc/nginx/ 2>/dev/null | head -5)

The question is whether anything on this machine terminates HTTP/2 for the internet, not which version it is.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

nginx

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSnginxNo advisory names itno advisory for this release names it
Ubuntu 24.04 LTSnginxNo advisory names itno advisory for this release names it
Debian 12 (bookworm)nginxNo fix releasedno fixed version released
Debian 13 (trixie)nginxFixed1.24.0-2
Rocky Linux 9nginxFixed1:1.22.1-3.module+el9.2.0+15280+45c505d6.1
AlmaLinux 9nginxFixed1:1.22.1-3.module_el9.2.0+44+f932b372.1.alma.1

Install the fix with apt update && apt install --only-upgrade nginx nginx-core on Debian and Ubuntu, or dnf update nginx on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

Apache HTTP Server

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSapache2No advisory names itno advisory for this release names it
Ubuntu 24.04 LTSapache2No advisory names itno advisory for this release names it
Debian 12 (bookworm)apache2No advisory names itno advisory for this release names it
Debian 13 (trixie)apache2No advisory names itno advisory for this release names it
Rocky Linux 9httpdNo advisory names itno advisory for this release names it
AlmaLinux 9httpdNo advisory names itno advisory for this release names it

Install the fix with apt update && apt install --only-upgrade apache2 apache2-bin on Debian and Ubuntu, or dnf update httpd httpd-core on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Recorded from nvd. Its weakness class is CWE-400, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-44487 included. It changes nothing.