[CLSA-2026:1788178281] mod_http2: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-31 14:04:17 UTC
Description:
- CVE-2026-48913: register input beam callbacks only after the input pipe is created, to avoid a use-after-free when file handles are exhausted
Updated packages:
  • mod_http2-2.0.26-4.el9_6.1.tuxcare.els5.x86_64.rpm
    sha:0d7cdfd4b31bb4371f4ef85d6a74c7824e7526af50b8212af062def4f6c80bfe
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.