ELSA-2026-55772 - haproxy security update
| Type: | SECURITY |
| Impact: | IMPORTANT |
| Release Date: | 2026-08-17 |
Description
[2.8.14-3.2]
- Fix NULL pointer dereference in hpack_dht_insert() (CVE-2026-55204)
Resolves: RHEL-211082
[2.8.14-3.1]
- Fix uint16_t overflow in FCGI demux record length (CVE-2026-55203)
Resolves: RHEL-211062
Related CVEs
Updated Packages
| Release/Architecture | Filename | sha256 | Superseded By Advisory | Channel Label |
|
| Oracle Linux 9 (aarch64) | haproxy-2.8.14-3.el9_8.2.src.rpm | 39932aae4fc1b93c27b1b00000abe536bf89582890065ece5545215d75ceb36f | - | ol9_aarch64_appstream |
| haproxy-2.8.14-3.el9_8.2.aarch64.rpm | 31c539b0d04de38c2abf9905d52e9967228bd21582a1ca53f6275a58db396249 | - | ol9_aarch64_appstream |
|
| Oracle Linux 9 (x86_64) | haproxy-2.8.14-3.el9_8.2.src.rpm | 39932aae4fc1b93c27b1b00000abe536bf89582890065ece5545215d75ceb36f | - | ol9_x86_64_appstream |
| haproxy-2.8.14-3.el9_8.2.x86_64.rpm | fc7cfaa55dc44f53b01d7482293d79d881db3a6e5eaba133ac88b113803122c1 | - | ol9_x86_64_appstream |
This page is generated automatically and has not been checked for errors or omissions. For clarification
or corrections please contact the Oracle Linux ULN team