Three issues have been identified in the nginx web server (CVE-2019-9511, CVE-2019-9513, CVE-2019-9516), leading to excessive memory consumption when using the module ngx_http_v2_module and implemented from the HTTP/2 protocol. The affected versions range from 1.9.5 to 1.17.2. Fixes have been made in nginx 1.16.1 (stable branch) and 1.17.3 (main branch). The problems were discovered by Jonathan Looney from Netflix.
The release 1.17.3 also includes two more fixes:
- Fix: when using compression, log messages 'zero size buf' could appear; the error was introduced in 1.17.2.
- Fix: a segmentation fault could occur in the worker process when using the resolver directive in SMTP proxy-server в рабочем процессе мог произойти segmentation fault.
Source: linux.org.ru
