You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note:Versions mentioned in the description apply only to the upstream nghttp2 package and not the nghttp2 package as distributed by Debian. See How to fix? for Debian:11 relevant fixed versions and status.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Upgrade Debian:11nghttp2 to version 1.43.0-1+deb11u1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream
nghttp2package and not thenghttp2package as distributed byDebian.See
How to fix?forDebian:11relevant fixed versions and status.The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Remediation
Upgrade
Debian:11nghttp2to version 1.43.0-1+deb11u1 or higher.References
rpxyjunkurihara/rust-rpxy#97