Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42: lua-http CVE-2023-4540 Critical DoS Mitigation

fedora
Calendar Grey June 4, 2025
Dist Fedora Esm H88
The lua-http library's patch for CVE-2023-4540 enhances protection against Denial of Service threats, boosting resilience in Fedora 42.
lua-http fix of CVE-2023-4540

Summary

lua-http is an efficient, capable HTTP and WebSocket library for Lua.

Update Information:

lua-http fix of CVE-2023-4540

Change Log

* Mon May 26 2025 Jakub Ružička - 0.3-17 - Fix CVE-2023-4540 (rhbz#2237419)

References


[ 1 ] Bug #2237419 - CVE-2023-4540 lua-http: lua-http library allows Excessive Allocation and a denial of service (DoS) attack https://bugzilla.redhat.com/show_bug.cgi?id=2237419

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-82090f2bcc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: lua-http
Product: Fedora 42
Version: 0.3
Release: 17.fc42
Summary: HTTP library for Lua

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here