[CLSA-2026:1784545904] Fix CVE(s): CVE-2026-55204
Type:
security
Severity:
Important
Release date:
2026-07-20 11:12:06 UTC
Description:
* SECURITY UPDATE: NULL pointer dereference in the HPACK decoder leading to a worker crash (denial of service) - debian/patches/CVE-2026-55204.patch: add missing NULL check after hpack_dht_defrag() in hpack_dht_insert() when the HPACK dynamic table memory pool is exhausted - CVE-2026-55204
CVEs fixed:
Updated packages:
  • haproxy_1.8.8-1ubuntu0.13.tuxcare.els3_amd64.deb
    sha:805fea0e6393799c2c805855d3aa226b89b7c7cb
  • haproxy-doc_1.8.8-1ubuntu0.13.tuxcare.els3_all.deb
    sha:2ed1e215c5efc798b24e40225f49550d0505faca
  • vim-haproxy_1.8.8-1ubuntu0.13.tuxcare.els3_all.deb
    sha:e35d2c92b8089c5defb793a77e7e7a6bdfbbf8ff
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.