[ALSA-2023:6746] Important: nghttp2 security update
Type:
security
Severity:
important
Release date:
2023-11-14
Description:
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C. Security Fix(es): * HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack) (CVE-2023-44487) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libnghttp2-devel-1.43.0-5.el9_3.1.aarch64.rpm 80aebb9d9b841025c63ffc171cccb861f20f41543ac92c390230da2241c605fd
aarch64 nghttp2-1.43.0-5.el9_3.1.aarch64.rpm 89c013dafe253eb014003fd423940c45252c09decdfd44579d3f7962eea55838
aarch64 libnghttp2-1.43.0-5.el9_3.1.aarch64.rpm b68d8048e6a6785c490b50a7538d06acaa168121e91c099646c2bec921710294
i686 libnghttp2-devel-1.43.0-5.el9_3.1.i686.rpm 7641771f23ec85bbc35220eb12d11fb59ce3eaad791a53aff950dcb2240b0d44
i686 libnghttp2-1.43.0-5.el9_3.1.i686.rpm ed7f0cddf6403bef1570fba9a55c61a29faf92aa95c488056b350d21642b5cbd
ppc64le libnghttp2-devel-1.43.0-5.el9_3.1.ppc64le.rpm 14e2b35c5138e7c902dac4b52319af69a0b769aace3a8f54b7c87c3ef86b1789
ppc64le nghttp2-1.43.0-5.el9_3.1.ppc64le.rpm a268e506a7a0abdf129be5ce1b73a77035c41735cd90d6eac5c1e388a3bc9551
ppc64le libnghttp2-1.43.0-5.el9_3.1.ppc64le.rpm b20cb8dbbb8d4c1d8df55eebabb4efe580f331234b2e08ed52d1ed4e8433c946
s390x nghttp2-1.43.0-5.el9_3.1.s390x.rpm 3a7bdbddeb6ce6adf9e3447266cd55eee62606a8d5597b40acb22fc9d84c391c
s390x libnghttp2-1.43.0-5.el9_3.1.s390x.rpm 64d957eebaa60cfa635c34eddf22ceec916422e718e14a0cb0e281d4799981ab
s390x libnghttp2-devel-1.43.0-5.el9_3.1.s390x.rpm 96e5384458b3113d7cc72816d7754f86f4adf0580eec7fdae3fa6480981b5e49
x86_64 nghttp2-1.43.0-5.el9_3.1.x86_64.rpm 2bde5de5b928091efbc7d74f61f002b4276d5aa1acbfcbb8d3d78a2533a8ee32
x86_64 libnghttp2-1.43.0-5.el9_3.1.x86_64.rpm a203db9a111bf805f65760f32cd24c346783e74fbbfc52ad484b3c208f2f2595
x86_64 libnghttp2-devel-1.43.0-5.el9_3.1.x86_64.rpm b7b9f36fcecddae9a8130ab1dd30b9c8841db1700956bcaaa9291320a24ced6a
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.