First published: Thu Apr 10 2025(Updated: )
Aleandro Prudenzano and Edoardo Geraci discovered that HAProxy incorrectly handled certain uncommon configurations that replace multiple short patterns with a longer one. A remote attacker could use this issue to cause HAProxy to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/haproxy | <2.9.10-1ubuntu1.2 | 2.9.10-1ubuntu1.2 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/haproxy | <2.8.5-1ubuntu3.3 | 2.8.5-1ubuntu3.3 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/haproxy | <2.4.24-0ubuntu0.22.04.2 | 2.4.24-0ubuntu0.22.04.2 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-7431-1 is considered important due to the potential for denial of service.
To fix USN-7431-1, update HAProxy to the latest versions listed in the advisory.
USN-7431-1 affects HAProxy versions up to 2.9.10-1ubuntu1.2, 2.8.5-1ubuntu3.3, and 2.4.24-0ubuntu0.22.04.2.
The impact of USN-7431-1 includes the potential for HAProxy to crash, leading to a denial of service.
The USN-7431-1 vulnerability was discovered by Aleandro Prudenzano and Edoardo Geraci.