RHSA-2024:3665: Moderate: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: CONTINUATION frames DoS (CVE-2024-28182,VU#421644.5) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3665?
The severity of RHSA-2024:3665 is rated as moderate due to the potential impact of the CONTINUATION frames DoS vulnerability.
How do I fix RHSA-2024:3665?
To fix RHSA-2024:3665, update the nghttp2 and libnghttp2 packages to version 1.43.0-5.el9_2.3 or later.
What vulnerabilities are addressed in RHSA-2024:3665?
RHSA-2024:3665 addresses a denial of service vulnerability related to CONTINUATION frames (CVE-2024-28182, VU#421644.5).
Which systems are affected by RHSA-2024:3665?
RHSA-2024:3665 affects various versions of Red Hat Enterprise Linux, including ARM 64, IBM z Systems, and x86_64 platforms.
Is there a recommended action for users of affected systems regarding RHSA-2024:3665?
It is recommended that users of affected systems apply the security fix as soon as possible to mitigate the risk of denial of service.