[CLSA-2026:1778148827] nghttp2: Fix of CVE-2023-35945
Type:
security
Severity:
Important
Release date:
2026-05-07 10:13:57 UTC
Description:
- CVE-2023-35945: fix memory leak in nghttp2_session_mem_send_internal when on_stream_close_callback returns a fatal error during send-failure handling
Updated packages:
  • libnghttp2-1.43.0-6.el9.tuxcare.els2.i686.rpm
    sha:61681566f924f735d5dcba4b4786c11e65f2c4cc094ed557b72c66077a0eee62
  • libnghttp2-1.43.0-6.el9.tuxcare.els2.x86_64.rpm
    sha:7b3ee2a92630a5b9375b275972d7fd4d12e6501279cd55518ac1ebcb9ef3f939
  • libnghttp2-devel-1.43.0-6.el9.tuxcare.els2.i686.rpm
    sha:56fb0ba2aa131817aeb176d7c4da10aada4886781308fd8c9a0a756396386a32
  • libnghttp2-devel-1.43.0-6.el9.tuxcare.els2.x86_64.rpm
    sha:6c03c07026964d21557f22376c6c3bee23b54b16d746f6758115f8d0a72537a6
  • nghttp2-1.43.0-6.el9.tuxcare.els2.x86_64.rpm
    sha:70862a8ffdd6a1dbb3855c9c6e008ee8a4c0d1c919fb1dc90641425c1de26911
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.