[ALSA-2023:5838] Important: nghttp2 security update
Type:
security
Severity:
important
Release date:
2023-10-19
Description:
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C. Security Fix(es): * HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libnghttp2-1.43.0-5.el9_2.1.aarch64.rpm 78a489628725cdcf915d631c7d00f1b9e51f26c04b0c21f6c1bbe55a2ced3947
aarch64 libnghttp2-devel-1.43.0-5.el9_2.1.aarch64.rpm b8c9b97c9f48be0ca732dfde5d75731b1bc1afcf5e1b84aeb9373349f1b68872
aarch64 nghttp2-1.43.0-5.el9_2.1.aarch64.rpm feb0ded4795c8ffedfe2319e96cb926a23fbb9d4d59d7921df6c37e43f8303ff
i686 libnghttp2-devel-1.43.0-5.el9_2.1.i686.rpm 8b5d87b4d2e966a99c10098707a8bcecddc50e7eaaa737a1a1670ec6e939031f
i686 libnghttp2-1.43.0-5.el9_2.1.i686.rpm a8f829041cfe9ff31216adb614b2a67edb759fbc9139b8d3c779669622957d2f
ppc64le nghttp2-1.43.0-5.el9_2.1.ppc64le.rpm 483f30d1823a5e9515b384c1b63ed0468eaa03f2db92511a166a9bdf8a2d9bbf
ppc64le libnghttp2-1.43.0-5.el9_2.1.ppc64le.rpm a9501b1bd929dd91a3a65e9383515b97d88a8f226403d2df8c336a45370afd1a
ppc64le libnghttp2-devel-1.43.0-5.el9_2.1.ppc64le.rpm d3a72706496722d56477d16dff11004a467d8451d4ff754934f9d0394801086a
s390x libnghttp2-1.43.0-5.el9_2.1.s390x.rpm 49111f368c79f2135565fdcd62da4efa1d94098f212ab78a4007ab12e91598f9
s390x nghttp2-1.43.0-5.el9_2.1.s390x.rpm 4a349dcd81731ed6e9f85960a1cfd3378e785c45e41683be7d06acdfc052bb8e
s390x libnghttp2-devel-1.43.0-5.el9_2.1.s390x.rpm fbd4ef9bfbb683f06954802afa1c07c4239e816089f2bafcb4bc4f7f9a7f11b3
x86_64 libnghttp2-1.43.0-5.el9_2.1.x86_64.rpm 3a60580cb909cf653450cafb61154092a0effedaffb15877703eea203c40724b
x86_64 nghttp2-1.43.0-5.el9_2.1.x86_64.rpm 3d07b2ab8d2e4a449dc542a9826fc1ce03855272392e9dfb084512e77c7ae24f
x86_64 libnghttp2-devel-1.43.0-5.el9_2.1.x86_64.rpm 8204feaa82213c138b7567ccebe28e185786a5a1b79869fc5c159cfaf3c1368e
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.