Ubuntu Security Update USN-8233-2: nghttp2 vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,768
Reaction score
74
Credits
-1,257
USN-8233-1 fixed a vulnerability in nghttp2. This update provides the corresponding update for Ubuntu 26.04 LTS. Original advisory details: Andrew MacPherson discovered that nghttp2 did not properly validate internal state when the session termination API was called. A remote attacker could possibly use this issue to cause nghttp2 to crash, resulting in a denial of service.

Continue reading...
 


Follow Linux.org

Members online


Top