RHSA-2024:2700: Important: varnish security update
Important: varnish security update
Other sources
Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up.Security Fix(es): varnish: HTTP/2 Broken Window Attack may result in denial of service (CVE-2024-30156) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2700?
The severity of RHSA-2024:2700 is classified as important.
How do I fix RHSA-2024:2700?
To fix RHSA-2024:2700, upgrade the varnish package to version 6.6.2-2.el9_0.3 or later.
What products are affected by RHSA-2024:2700?
RHSA-2024:2700 affects multiple Red Hat Enterprise Linux products for ARM 64, x86_64, Power LE, and IBM z Systems.
What is the nature of the vulnerability in RHSA-2024:2700?
RHSA-2024:2700 addresses a security flaw found in the HTTP/2 implementation in Varnish Cache.
Is there a documentation update associated with RHSA-2024:2700?
Yes, the varnish-docs package also needs to be updated to version 6.6.2-2.el9_0.3 to resolve the vulnerability.