Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3154-1

Опубликовано: 21 июл. 2026
Источник: suse-cvrf

Описание

Security update for nghttp2

This update for nghttp2 fixes the following issue

  • CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489).

Список пакетов

SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
libnghttp2-14-1.39.2-3.26.1
libnghttp2-14-32bit-1.39.2-3.26.1
libnghttp2-devel-1.39.2-3.26.1

Описание

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.


Затронутые продукты
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libnghttp2-14-1.39.2-3.26.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libnghttp2-14-32bit-1.39.2-3.26.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:libnghttp2-devel-1.39.2-3.26.1

Ссылки