INFSA-2024:4252: nghttp2 security update

Information about definition

Identificator: INFSA-2024:4252

Type: security

Release date: 2024-08-23 19:04:38 UTC

Information about package

libnghttp2 is a library implementing the Hypertext Transfer Protocol version 2 (HTTP/2) protocol in C.

Vulnerabilities description

  • CVE-2024-28182

    The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to keep HPACK context in sync. This causes excessive CPU usage to decode HPACK stream. nghttp2 v1.61.0 mitigates this vulnerability by limiting the number of CONTINUATION frames it accepts per stream. There is no workaround for this vulnerability.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 5.3 no information
Critical, important, moderate, low

Updated packages