RHSA-2024:3701: Moderate: nghttp2 security update
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.Security Fix(es): nghttp2: CONTINUATION frames DoS (CVE-2024-28182,VU#421644.5) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3701?
The severity of RHSA-2024:3701 is classified as moderate.
How do I fix RHSA-2024:3701?
To resolve RHSA-2024:3701, update your system with the package versions 1.33.0-5.el8_8.1 or higher of nghttp2 and libnghttp2.
Which systems are affected by RHSA-2024:3701?
RHSA-2024:3701 affects multiple versions of Red Hat Enterprise Linux and CodeReady Linux Builder for various architectures.
What is CVE-2024-28182 in relation to RHSA-2024:3701?
CVE-2024-28182 describes a denial-of-service vulnerability associated with CONTINUATION frames in nghttp2.
What does RHSA-2024:3701 address in libnghttp2?
RHSA-2024:3701 addresses a denial-of-service vulnerability that could lead to service interruptions in systems using libnghttp2.