[CLSA-2026:1777974095] nghttp2: Fix of CVE-2026-27135
Type:
security
Severity:
Important
Release date:
2026-05-05 12:20:57 UTC
Description:
- CVE-2026-27135: fix missing iframe->state validations to avoid assertion failure
Updated packages:
  • libnghttp2-1.43.0-6.el9.tuxcare.els1.i686.rpm
    sha:892ff3ec0fee8f15e8ce891535c1a95c7a077d9663231dce65968563a156084a
  • libnghttp2-1.43.0-6.el9.tuxcare.els1.x86_64.rpm
    sha:3e27be9c14be70a048e9da144b1b37e55b4fdadf1b260c97778b3890305ef5f3
  • libnghttp2-devel-1.43.0-6.el9.tuxcare.els1.i686.rpm
    sha:b37dc196d14c4ecfabe50ca05528c224a6da4143366050f4b146e5b819a89c9f
  • libnghttp2-devel-1.43.0-6.el9.tuxcare.els1.x86_64.rpm
    sha:03dc8ef1a6c2450d6a28214d5fa2d1e892b6aa5fe5b08c8c4335b709e36d7806
  • nghttp2-1.43.0-6.el9.tuxcare.els1.x86_64.rpm
    sha:2cb07daf25008ddabba11ab9a28a417e7afcebc2c1cadcedfb6b93efd4652bdc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.