Debian Rust-H2 vulnerabilities
2 known vulnerabilities affecting debian/rust-h2.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2023-26964HIGHCVSS 7.5fixed in rust-h2 0.3.13-2 (bookworm)2023
CVE-2023-26964 [HIGH] CVE-2023-26964: rust-h2 - An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when t...
An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).
Scope: local
bookworm: resolved (fixed in 0.3.13-2)
forky: resolved (fixed in 0.3.13-2)
sid: resolved (fixed in 0.3.13-2)
trixie: resolved (fixed
debian
CVE-2019-9514HIGHCVSS 7.5fixed in h2o 2.2.5+dfsg2-3 (bookworm)2019
CVE-2019-9514 [HIGH] CVE-2019-9514: h2o - Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading...
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
Scope: local
book
debian