[CLSA-2026:1788175030] Fix CVE(s): CVE-2020-11080, CVE-2023-35945, CVE-2023-44487
Type:
security
Severity:
Important
Release date:
2026-08-31 11:17:24 UTC
Description:
* SECURITY UPDATE: denial of service via HTTP/2 stream reset flood (Rapid Reset) - debian/patches/CVE-2023-44487.patch: rate-limit incoming RST_STREAM on server sessions with a token bucket (burst 1000, 33 tokens per second) and send GOAWAY once it is exhausted, adding the nghttp2_ratelim and nghttp2_time modules and the clock_gettime / GetTickCount64 probes they need. Backported without upstream's new public option setter, so debian/libnghttp2-14.symbols is unchanged. - CVE-2023-44487
Updated packages:
  • libnghttp2-14_1.30.0-1ubuntu1+tuxcare.els3_amd64.deb
    sha:6b378893cc13eb560329b671f7d156dd1cef48f0
  • libnghttp2-dev_1.30.0-1ubuntu1+tuxcare.els3_amd64.deb
    sha:dc390f63640e8cc9a964690fc5c9c2498526f1b9
  • libnghttp2-doc_1.30.0-1ubuntu1+tuxcare.els3_all.deb
    sha:1e5110732b2716a8dd76b82a7f874a113f8da26b
  • nghttp2_1.30.0-1ubuntu1+tuxcare.els3_all.deb
    sha:a4cf01de60c3aa9194155318c17b62ce329155d4
  • nghttp2-client_1.30.0-1ubuntu1+tuxcare.els3_amd64.deb
    sha:b6fba4fd77e6228cc7850d486ceb4cf9b7c629b1
  • nghttp2-proxy_1.30.0-1ubuntu1+tuxcare.els3_amd64.deb
    sha:046f187b37d7a8b2d10e620ba330fc87533b30c9
  • nghttp2-server_1.30.0-1ubuntu1+tuxcare.els3_amd64.deb
    sha:59c121c2d8bb70a86a992ffc8a71fdbd3f304832
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.