USN-7469-4: H2O vulnerability
30 April 2025
H2O could be made to crash if it received specially crafted network traffic.
Releases
Packages
- h2o - an optimized HTTP server with support for HTTP/1.x, HTTP/2, and HTTP/3
Details
USN-7469-1 fixed a vulnerability in Apache Traffic Server. This update
provides the corresponding updates for H2O.
Original advisory details:
It was discovered that Apache Traffic Server exhibited poor server
resource management in its HTTP/2 protocol. An attacker could possibly
use this issue to cause Apache Traffic Server to crash, resulting in
a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.04
-
h2o
-
2.2.4+dfsg-1ubuntu0.1~esm2
Available with Ubuntu Pro
-
libh2o0.13
-
2.2.4+dfsg-1ubuntu0.1~esm2
Available with Ubuntu Pro
After a standard system update you need to restart H2O to make all the
necessary changes.