First published: Wed Jun 12 2024(Updated: )
libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.<br>Security Fix(es):<br><li> nghttp2: CONTINUATION frames DoS (CVE-2024-28182,VU#421644.5)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nghttp2 | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2 | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2-debuginfo | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/nghttp2-debuginfo | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/nghttp2-debugsource | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2 | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2 | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2-debuginfo | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2-debuginfo | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/nghttp2-debuginfo | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/nghttp2-debuginfo | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/nghttp2-debugsource | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/nghttp2-debugsource | <1.43.0-5.el9_0.3 | 1.43.0-5.el9_0.3 |
redhat/libnghttp2 | <1.43.0-5.el9_0.3.aa | 1.43.0-5.el9_0.3.aa |
redhat/libnghttp2-debuginfo | <1.43.0-5.el9_0.3.aa | 1.43.0-5.el9_0.3.aa |
redhat/nghttp2-debuginfo | <1.43.0-5.el9_0.3.aa | 1.43.0-5.el9_0.3.aa |
redhat/nghttp2-debugsource | <1.43.0-5.el9_0.3.aa | 1.43.0-5.el9_0.3.aa |
Red Hat Enterprise Linux Server for IBM z Systems | ||
Red Hat Enterprise Linux Server | ||
Red Hat Enterprise Linux for SAP Solutions | ||
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2024:3875 is classified as moderate due to the denial-of-service vulnerability in nghttp2.
To fix RHSA-2024:3875, update the nghttp2 and libnghttp2 packages to version 1.43.0-5.el9_0.3 or later.
RHSA-2024:3875 affects various versions of Red Hat Enterprise Linux across multiple architectures including IBM z Systems, ARM 64, x86_64, and Power LE.
CVE-2024-28182 is the identifier for the vulnerability that allows for denial-of-service through CONTINUATION frames in HTTP/2.
Yes, you need to upgrade to the package version 1.43.0-5.el9_0.3 for proper remediation of RHSA-2024:3875.