{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu20.04els/vex/2023/cve-2023-0056-els_os-ubuntu20_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-10T02:15:46Z",
      "generator": {
        "date": "2026-07-10T02:15:46Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-0056-ELS_OS-UBUNTU20.04ELS",
      "initial_release_date": "2023-03-23T21:15:00Z",
      "revision_history": [
        {
          "date": "2023-03-23T21:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-10T02:15:46Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2023-0056"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 20.04",
                "product": {
                  "name": "Ubuntu 20.04",
                  "product_id": "Ubuntu-20",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "haproxy-0:2.0.33-0ubuntu0.1.amd64",
                "product": {
                  "name": "haproxy-0:2.0.33-0ubuntu0.1.amd64",
                  "product_id": "haproxy-0:2.0.33-0ubuntu0.1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/haproxy@2.0.33-0ubuntu0.1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "vim-haproxy-0:2.0.33-0ubuntu0.1.all",
                "product": {
                  "name": "vim-haproxy-0:2.0.33-0ubuntu0.1.all",
                  "product_id": "vim-haproxy-0:2.0.33-0ubuntu0.1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/vim-haproxy@2.0.33-0ubuntu0.1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "haproxy-doc-0:2.0.33-0ubuntu0.1.all",
                "product": {
                  "name": "haproxy-doc-0:2.0.33-0ubuntu0.1.all",
                  "product_id": "haproxy-doc-0:2.0.33-0ubuntu0.1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/haproxy-doc@2.0.33-0ubuntu0.1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
                "product": {
                  "name": "haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
                  "product_id": "haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/haproxy@2.0.33-0ubuntu0.1%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
                "product": {
                  "name": "vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
                  "product_id": "vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/vim-haproxy@2.0.33-0ubuntu0.1%2Btuxcare.els1?arch=all"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
                "product": {
                  "name": "haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
                  "product_id": "haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/haproxy-doc@2.0.33-0ubuntu0.1%2Btuxcare.els1?arch=all"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "all"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64"
        },
        "product_reference": "haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "haproxy-0:2.0.33-0ubuntu0.1.amd64 as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1.amd64"
        },
        "product_reference": "haproxy-0:2.0.33-0ubuntu0.1.amd64",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all"
        },
        "product_reference": "vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vim-haproxy-0:2.0.33-0ubuntu0.1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1.all"
        },
        "product_reference": "vim-haproxy-0:2.0.33-0ubuntu0.1.all",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all"
        },
        "product_reference": "haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
        "relates_to_product_reference": "Ubuntu-20"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "haproxy-doc-0:2.0.33-0ubuntu0.1.all as a component of Ubuntu 20.04",
          "product_id": "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1.all"
        },
        "product_reference": "haproxy-doc-0:2.0.33-0ubuntu0.1.all",
        "relates_to_product_reference": "Ubuntu-20"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-0056",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
          "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1.amd64",
          "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
          "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1.all",
          "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
          "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1.all"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-0056"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2023-0056",
          "url": "https://access.redhat.com/security/cve/CVE-2023-0056"
        }
      ],
      "release_date": "2023-03-23T21:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-09T12:06:50.841032Z",
          "details": "Deprioritize: CVE-2023-0056 is a denial‑of‑service issue in HAProxy’s HTTP/2 response handling that only affects availability, with no confidentiality or integrity impact. Exploitation requires authenticated access to an OpenShift cluster to run a backend server that HAProxy will contact, rather than simply sending crafted client requests—an attack precondition that does not exist when backends are administrator‑controlled. The flaw has been fixed upstream and backported by major distributions since January 2023, further reducing residual exposure.",
          "product_ids": [
            "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
            "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1.amd64",
            "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
            "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1.all",
            "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
            "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1.all"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.amd64",
            "Ubuntu-20:haproxy-0:2.0.33-0ubuntu0.1.amd64",
            "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
            "Ubuntu-20:haproxy-doc-0:2.0.33-0ubuntu0.1.all",
            "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1+tuxcare.els1.all",
            "Ubuntu-20:vim-haproxy-0:2.0.33-0ubuntu0.1.all"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}