Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Fedora 44 ngtcp2 Critical Denial of Service Fix CVE-2026-40170

fedora
Calendar Grey April 28, 2026
Dist Fedora Esm H88
Fedora 44 ngtcp2 1.22.1 update fixes CVE-2026-40170 critical buffer overflow issue.
Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170

Summary

"Call it TCP/2. One More Time."

ngtcp2 project is an effort to implement RFC9000 QUIC protocol.

Update Information:

Update to 1.22.1 (rhbz#2452790) Fixes CVE-2026-40170

Change Log

* Mon Apr 20 2026 Petr Men\u0161k - 1.22.1-1 - Update to 1.22.1 (rhbz#2452790) - Fixes CVE-2026-40170

References


[ 1 ] Bug #2452790 - ngtcp2-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2452790 [ 2 ] Bug #2459283 - CVE-2026-40170 ngtcp2: ngtcp2: Denial of service via stack buffer overflow during QUIC handshake [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459283

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-705eb9cf95' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: ngtcp2
Product: Fedora 44
Version: 1.22.1
Release: 1.fc44
Summary: Implementation of RFC 9000 QUIC protocol

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here