Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-44453

Опубликовано: 16 июл. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca. The maximum size of the memory allocated using alloca can be as huge as ~600KB, which exceeds the default pthread stack size used by musl libc (128KB). If the amount of memory allocated by alloca exceeds the stack size, the h2o server crashes with a segmentation fault, while it tries to touch the guard page. This issue has been fixed by commit 6b5370d.

РелизСтатусПримечание
devel

not-affected

no longer depends on h2o
esm-apps-legacy/xenial

not-affected

dns over https not implemented
esm-apps/bionic

not-affected

dns over https not implemented
esm-apps/focal

not-affected

uses system h2o
esm-apps/jammy

not-affected

uses system h2o
esm-apps/noble

needs-triage

esm-apps/resolute

not-affected

no longer depends on h2o
jammy

not-affected

uses system h2o
noble

needs-triage

resolute

not-affected

no longer depends on h2o

Показывать по

РелизСтатусПримечание
devel

DNE

esm-apps/bionic

needs-triage

esm-apps/focal

needs-triage

esm-apps/jammy

needs-triage

esm-apps/noble

needs-triage

jammy

needs-triage

noble

needs-triage

resolute

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 20%
0.00279
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
28 дней назад

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca. The maximum size of the memory allocated using alloca can be as huge as ~600KB, which exceeds the default pthread stack size used by musl libc (128KB). If the amount of memory allocated by alloca exceeds the stack size, the h2o server crashes with a segmentation fault, while it tries to touch the guard page. This issue has been fixed by commit 6b5370d.

CVSS3: 7.5
debian
28 дней назад

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...

EPSS

Процентиль: 20%
0.00279
Низкий

7.5 High

CVSS3