Skip to content

CVE-2023-44487 SNYK-UBUNTU2204-NGHTTP2-5954819 #4843

@github-actions

Description

@github-actions

NVD Description

Note: Versions mentioned in the description apply only to the upstream nghttp2 package and not the nghttp2 package as distributed by Ubuntu.
See How to fix? for Ubuntu:22.04 relevant fixed versions and status.

The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.

Remediation

Upgrade Ubuntu:22.04 nghttp2 to version 1.43.0-1ubuntu0.1 or higher.

References

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions