ELSA-2023-5924

ELSA-2023-5924 - varnish security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2023-10-24

Description


[6.6.2-3.el9_2.1]
- Add parameters h2_rst_allowance and h2_rst_allowance_period to mitigate CVE-2023-44487
- Resolves: RHEL-12818


Related CVEs


CVE-2023-44487

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) varnish-6.6.2-3.el9_2.1.src.rpm0339fa46ff1ea43dd7fae3d5e99561ec1d57566b4524100eb7cbed4a8dc71eba-ol9_aarch64_appstream
varnish-6.6.2-3.el9_2.1.src.rpm0339fa46ff1ea43dd7fae3d5e99561ec1d57566b4524100eb7cbed4a8dc71eba-ol9_aarch64_codeready_builder
varnish-6.6.2-3.el9_2.1.aarch64.rpm87f3257deb4458033c2ca511e4e684592dc838d6e34e4988e8a0786b188f5b8e-ol9_aarch64_appstream
varnish-devel-6.6.2-3.el9_2.1.aarch64.rpmd499d82dcd7fd8fe938b67f0f33a171eef8c144ba213238bbe2bf204c3447f36-ol9_aarch64_codeready_builder
varnish-docs-6.6.2-3.el9_2.1.aarch64.rpmb1b88be30c41f91f3fedd53fb4c8e6f06a0ebee408bb44dbd04a90982aa7ac30-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) varnish-6.6.2-3.el9_2.1.src.rpm0339fa46ff1ea43dd7fae3d5e99561ec1d57566b4524100eb7cbed4a8dc71eba-ol9_x86_64_appstream
varnish-6.6.2-3.el9_2.1.src.rpm0339fa46ff1ea43dd7fae3d5e99561ec1d57566b4524100eb7cbed4a8dc71eba-ol9_x86_64_codeready_builder
varnish-6.6.2-3.el9_2.1.i686.rpmecdc402596720f0ecd1cb7a781b993b2df8dc8b297ec32d3f4c6ecf96c890a0c-ol9_x86_64_appstream
varnish-6.6.2-3.el9_2.1.x86_64.rpmfbea308dcd150af2b77ce926cf4517fd1221a36447b5d4b7900d6eae9a660f13-ol9_x86_64_appstream
varnish-devel-6.6.2-3.el9_2.1.i686.rpme44da042249874c338643bf722dba9f56295a1ea788e0948f5ff4c4ad26cc55a-ol9_x86_64_codeready_builder
varnish-devel-6.6.2-3.el9_2.1.x86_64.rpm488fe269e7fccb6e31fc6b763fd56bdad95e46fa848cf8a35e072e635c9531a7-ol9_x86_64_codeready_builder
varnish-docs-6.6.2-3.el9_2.1.x86_64.rpm6b6d6e3a0c4f9d63b50adaf4bb2e73958501e5822ec31a19def06cd9d73b2f9e-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete