{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/vex/2024/cve-2024-2398-els_os-ubuntu18_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-31T15:13:14Z",
      "generator": {
        "date": "2026-08-31T15:13:14Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2024-2398-ELS_OS-UBUNTU18.04ELS",
      "initial_release_date": "2024-03-27T08:15:00Z",
      "revision_history": [
        {
          "date": "2024-03-27T08:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-31T15:13:14Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2024-2398"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all",
                "product": {
                  "name": "libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all",
                  "product_id": "libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libnghttp2-doc@1.30.0-1ubuntu1%2Btuxcare.els3?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all",
                "product": {
                  "name": "nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all",
                  "product_id": "nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/nghttp2@1.30.0-1ubuntu1%2Btuxcare.els3?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                "product": {
                  "name": "nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_id": "nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/nghttp2-client@1.30.0-1ubuntu1%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                "product": {
                  "name": "libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_id": "libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libnghttp2-dev@1.30.0-1ubuntu1%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                "product": {
                  "name": "nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_id": "nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/nghttp2-server@1.30.0-1ubuntu1%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                "product": {
                  "name": "libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_id": "libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libnghttp2-14@1.30.0-1ubuntu1%2Btuxcare.els3?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                "product": {
                  "name": "nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_id": "nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/nghttp2-proxy@1.30.0-1ubuntu1%2Btuxcare.els3?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all"
        },
        "product_reference": "libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
        },
        "product_reference": "nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
        },
        "product_reference": "libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
        },
        "product_reference": "nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all"
        },
        "product_reference": "nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
        },
        "product_reference": "libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
        },
        "product_reference": "nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-2398",
      "cwe": {
        "id": "CWE-772",
        "name": "Missing Release of Resource after Effective Lifetime"
      },
      "notes": [
        {
          "category": "description",
          "text": "When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory.  Further, this error condition fails silently and is therefore not easily detected by an application.",
          "title": "Vulnerability description"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "Ubuntu-18:libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
          "Ubuntu-18:libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
          "Ubuntu-18:libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all",
          "Ubuntu-18:nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all",
          "Ubuntu-18:nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
          "Ubuntu-18:nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
          "Ubuntu-18:nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2024-2398"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2024/Jul/18",
          "url": "http://seclists.org/fulldisclosure/2024/Jul/18"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2024/Jul/19",
          "url": "http://seclists.org/fulldisclosure/2024/Jul/19"
        },
        {
          "category": "external",
          "summary": "http://seclists.org/fulldisclosure/2024/Jul/20",
          "url": "http://seclists.org/fulldisclosure/2024/Jul/20"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2024/03/27/3",
          "url": "http://www.openwall.com/lists/oss-security/2024/03/27/3"
        },
        {
          "category": "external",
          "summary": "https://curl.se/docs/CVE-2024-2398.html",
          "url": "https://curl.se/docs/CVE-2024-2398.html"
        },
        {
          "category": "external",
          "summary": "https://curl.se/docs/CVE-2024-2398.json",
          "url": "https://curl.se/docs/CVE-2024-2398.json"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2402845",
          "url": "https://hackerone.com/reports/2402845"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2D44YLAUFJU6BZ4XFG2FYV7SBKXB5IZ6/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GMD6UYKCCRCYETWQZUJ65ZRFULT6SHLI/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240503-0009/",
          "url": "https://security.netapp.com/advisory/ntap-20240503-0009/"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/kb/HT214118",
          "url": "https://support.apple.com/kb/HT214118"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/kb/HT214119",
          "url": "https://support.apple.com/kb/HT214119"
        },
        {
          "category": "external",
          "summary": "https://support.apple.com/kb/HT214120",
          "url": "https://support.apple.com/kb/HT214120"
        }
      ],
      "release_date": "2024-03-27T08:15:00Z",
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "date": "2026-08-21T21:12:21.785017Z",
          "details": "This flaw is a memory leak in the HTTP/2 server-push handling of the HTTP client library libcurl, where header fields accumulated for an aborted push are not released. The affected accumulator and its header-count limit belong entirely to that client library; this package implements only the HTTP/2 PUSH_PROMISE protocol exchange and passes header fields to the calling application without retaining them. The vulnerable code is therefore not present in this package.",
          "product_ids": [
            "Ubuntu-18:libnghttp2-14-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
            "Ubuntu-18:libnghttp2-dev-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
            "Ubuntu-18:libnghttp2-doc-0:1.30.0-1ubuntu1+tuxcare.els3.all",
            "Ubuntu-18:nghttp2-0:1.30.0-1ubuntu1+tuxcare.els3.all",
            "Ubuntu-18:nghttp2-client-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
            "Ubuntu-18:nghttp2-proxy-0:1.30.0-1ubuntu1+tuxcare.els3.amd64",
            "Ubuntu-18:nghttp2-server-0:1.30.0-1ubuntu1+tuxcare.els3.amd64"
          ]
        }
      ]
    }
  ]
}