HTTP/2 Rapid Reset: a protocol flaw that turned into the largest attacks ever recorded
Not a memory bug. HTTP/2 lets a client open a request and cancel it immediately, and the cancellation costs the client nothing while costing the server real work. Doing that in a loop produced denial-of-service attacks an order of magnitude larger than anything seen before.
A fixed package version is available on 3 of the releases below. 1 has an advisory with no fix released. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
A client streams RST_STREAM frames to cancel requests as fast as it can create them. The server keeps allocating and tearing down request state while the connection limit is never reached, because cancelled streams do not count against it.
What an attacker gets: Denial of service, at a scale that made it notable. No data disclosure and no code execution.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- HTTP/2 has to be enabled and reachable. A server behind a reverse proxy or a CDN that terminates HTTP/2 is protected by whatever that layer does, not by its own version.
- The fixes are rate limits and accounting changes rather than a single corrected line, so different servers addressed it differently and on different dates.
- This is the clearest case on this site of a CVE being about a protocol rather than a package. The table below shows nginx carrying advisories and Apache HTTP Server carrying none for these releases, which is a real difference and not a gap.
Check your own server
ss -lntp | grep -E ':(80|443)' && (nginx -V 2>&1 | grep -o with-http_v2_module; grep -rn 'http2' /etc/nginx/ 2>/dev/null | head -5)The question is whether anything on this machine terminates HTTP/2 for the internet, not which version it is.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
nginx
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | nginx | No advisory names it | no advisory for this release names it |
| Ubuntu 24.04 LTS | nginx | No advisory names it | no advisory for this release names it |
| Debian 12 (bookworm) | nginx | No fix released | no fixed version released |
| Debian 13 (trixie) | nginx | Fixed | 1.24.0-2 |
| Rocky Linux 9 | nginx | Fixed | 1:1.22.1-3.module+el9.2.0+15280+45c505d6.1 |
| AlmaLinux 9 | nginx | Fixed | 1:1.22.1-3.module_el9.2.0+44+f932b372.1.alma.1 |
Install the fix with apt update && apt install --only-upgrade nginx nginx-core on Debian and Ubuntu, or dnf update nginx on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
Apache HTTP Server
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | apache2 | No advisory names it | no advisory for this release names it |
| Ubuntu 24.04 LTS | apache2 | No advisory names it | no advisory for this release names it |
| Debian 12 (bookworm) | apache2 | No advisory names it | no advisory for this release names it |
| Debian 13 (trixie) | apache2 | No advisory names it | no advisory for this release names it |
| Rocky Linux 9 | httpd | No advisory names it | no advisory for this release names it |
| AlmaLinux 9 | httpd | No advisory names it | no advisory for this release names it |
Install the fix with apt update && apt install --only-upgrade apache2 apache2-bin on Debian and Ubuntu, or dnf update httpd httpd-core on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Recorded from nvd. Its weakness class is CWE-400, from NVD.
- http://www.openwall.com/lists/oss-security/2023/10/10/6
- http://www.openwall.com/lists/oss-security/2023/10/10/7
- http://www.openwall.com/lists/oss-security/2023/10/13/4
- http://www.openwall.com/lists/oss-security/2023/10/13/9
- http://www.openwall.com/lists/oss-security/2023/10/18/4
- http://www.openwall.com/lists/oss-security/2023/10/18/8
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-44487 included. It changes nothing.