[CLSA-2026:1787303674] Fix CVE(s): CVE-2026-27135
Type:
security
Severity:
Important
Release date:
2026-08-21 09:14:44 UTC
Description:
* SECURITY UPDATE: assertion failure in nghttp2 HTTP/2 frame processing - debian/patches/CVE-2026-27135-1.patch: add missing iframe->state validations in nghttp2_session_mem_recv so that reception stops once the session has been terminated, avoiding an assertion failure on a subsequent malformed frame - debian/patches/CVE-2026-27135-2.patch: add the same validation after session_after_header_block_received and after session_process_data_frame, which upstream carries since 1.67.0 and which the fix above therefore does not touch - CVE-2026-27135
CVEs fixed:
Updated packages:
  • libnghttp2-14_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb
    sha:47a59394be48fd54f841a8437f2749f23c466e07
  • libnghttp2-dev_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb
    sha:a542debb23ac59b850f643e7ec785154e8ed7d86
  • libnghttp2-doc_1.36.0-2+deb10u3+tuxcare.els2_all.deb
    sha:bd3a40897750d150f9ab20100b9b1aa4282488c8
  • nghttp2_1.36.0-2+deb10u3+tuxcare.els2_all.deb
    sha:8537dcd58d25d49113c7debd48424e4e74f70683
  • nghttp2-client_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb
    sha:bef46b2dddd2b2c9a958714f0d2c3a42a74bc54f
  • nghttp2-proxy_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb
    sha:4edb94d1908c6d8d2bdea4ce2a20127af173d239
  • nghttp2-server_1.36.0-2+deb10u3+tuxcare.els2_amd64.deb
    sha:e75c18a54bf39d10c5f5be793ca4ccdaaec05b89
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.