An out-of-bounds read issue was discovered in the HTTP/2 protocol decoder in HAProxy 1.8.x and 1.9.x through 1.9.0 which can result in a crash. The processing of the PRIORITY flag in a HEADERS frame requires 5 extra bytes, and while these bytes are skipped, the total frame length was not re-checked to make sure they were present in the frame.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade haproxy | Jul 30, 2024 | Mar 21, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade haproxy | Mar 23, 2020 | Mar 21, 2019 |
| Redhat Openshift | — | Upgrade atomic-openshift-deschedulerUpgrade atomic-openshift-metrics-serverUpgrade atomic-enterprise-service-catalogUpgrade jenkinsUpgrade openshift-enterprise-autohealUpgrade atomic-openshift-service-idlerUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-cluster-autoscalerUpgrade atomic-openshift-dockerregistryUpgrade haproxyUpgrade jenkins-2-pluginsUpgrade golang-github-prometheus-alertmanagerUpgrade openshift-ansibleUpgrade atomic-openshift-web-consoleUpgrade atomic-openshift-node-problem-detectorUpgrade golang-github-openshift-oauth-proxyUpgrade openshift-enterprise-cluster-capacityUpgrade golang-github-prometheus-prometheusUpgrade atomic-openshift | Mar 15, 2019 | Jan 8, 2019 |
| Suse | — | Upgrade haproxy | Feb 14, 2019 | Jan 15, 2019 |
| Ubuntu | — | Upgrade haproxy | Jan 23, 2019 | Jan 15, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Mar 18, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub