Today, aborted websocket connections to keep an open connection between ANCM and Kestrel due to a bug with websocket disconnect detection. If continued, internal ports would be exhausted, causing the server to effectively be DDOS’d.
This issue has been addressed in the following products: .NET Core on Red Hat Enterprise Linux Via RHSA-2019:0040 https://access.redhat.com/errata/RHSA-2019:0040
References: https://github.com/aspnet/Announcements/issues/335 https://github.com/aspnet/AspNetCore/issues/6488 https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0548