QID 242195

Date Published: 2023-10-19

QID 242195: Red Hat Update for nghttp2 (RHSA-2023:5838)

Libnghttp2 is a library implementing the hypertext transfer protocol version 2 (http/2) protocol in c...Security Fix(es):

    http/2: multiple http/2 enabled web servers are vulnerable to a ddos attack (rapid reset attack) (cve-2023-44487).
Affected Products:
    Red Hat enterprise linux for x86_64 9 x86_64.
    Red hat enterprise linux for x86_64 - extended update support 9.2 x86_64.
    Red hat enterprise linux server - aus 9.2 x86_64.
    Red hat enterprise linux for ibm z systems 9 s390x.
    Red hat enterprise linux for ibm z systems - extended update support 9.2 s390x.
    Red hat enterprise linux for power, little endian 9 ppc64le.
    Red hat enterprise linux for power, little endian - extended update support 9.2 ppc64le.
    Red hat enterprise linux for arm 64 9 aarch64.
    Red hat enterprise linux server for power le - update services for sap solutions 9.2 ppc64le.
    Red hat enterprise linux for x86_64 - update services for sap solutions 9.2 x86_64.
    Red hat codeready linux builder for x86_64 9 x86_64.
    Red hat codeready linux builder for power, little endian 9 ppc64le.
    Red hat codeready linux builder for arm 64 9 aarch64.
    Red hat codeready linux builder for ibm z systems 9 s390x.
    Red hat enterprise linux for arm 64 - extended update support 9.2 aarch64.
    Red hat codeready linux builder for x86_64 - extended update support 9.2 x86_64.
    Red hat codeready linux builder for power, little endian - extended update support 9.2 ppc64le.
    Red hat codeready linux builder for ibm z systems - extended update support 9.2 s390x.
    Red hat codeready linux builder for arm 64 - extended update support 9.2 aarch64.
    Red hat enterprise linux server for arm 64 - 4 years of updates 9.2 aarch64.
    Red hat enterprise linux server for ibm z systems - 4 years of updates 9.2 s390x.
.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Red Hat security advisory RHSA-2023:5838 for updates and patch information.
    Vendor References

    CVEs related to QID 242195

    Software Advisories
    Advisory ID Software Component Link
    RHSA-2023:5838 Red Hat Enterprise Linux URL Logo access.redhat.com/errata/RHSA-2023:5838