CVE-2023-39456: Apache Traffic Server: Malformed http/2 frames can cause an abort
Improper Input Validation vulnerability in Apache Traffic Server with malformed HTTP/2 frames.This issue affects Apache Traffic Server: from 9.0.0 through 9.2.2.
Users are recommended to upgrade to version 9.2.3, which fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-39456.
What is the severity of CVE-2023-39456?
CVE-2023-39456 has a severity level of 7.5 (High).
Which software is affected by CVE-2023-39456?
Apache Traffic Server versions 9.0.0 through 9.2.2 are affected by CVE-2023-39456.
How can I fix CVE-2023-39456?
Upgrade to Apache Traffic Server version 9.2.3, which includes the fix for CVE-2023-39456.
Are there any references available for CVE-2023-39456?
Yes, you can find more information about CVE-2023-39456 at the following references: [Reference 1](https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/).