Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia 9: Varnish Important DoS Threat MGASA-2025-0239 CVE-2025-8671

mageia
Calendar Grey October 17, 2025
Dist Mageia Esm H88
The Mageia security advisory highlights a critical DoS issue in Varnish affecting Mageia 9, requiring prompt action.
MGASA-2025-0239 - Updated varnish & lighttpd packages fix security vulnerability

Summary

Description: It was discovered that a denial of service attack can be performed on cache servers that have the HTTP/2 protocol turned on. An attacker can create a large number of streams and immediately reset them without ever reaching the maximum number of concurrent streams allowed for the session, causing the server to consume unnecessary resources processing requests for which the response will not be delivered (CVE-2025-8671).

References

- https://bugs.mageia.org/show_bug.cgi?id=34587

- https://www.openwall.com/lists/oss-security/2025/08/13/6

- https://www.openwall.com/lists/oss-security/2025/08/16/1

- https://www.cve.org/CVERecord?id=CVE-2025-8671

Resolution

SRPMS

- 9/core/varnish-7.7.3-1.mga9

- 9/core/lighttpd-1.4.80-1.3.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 17 Oct 2025
URL: https://advisories.mageia.org/MGASA-2025-0239.html
Type: security
CVE: CVE-2025-8671

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here