Description:
Haproxy has a critical, a major, few medium and few minor bugs fixed in the
last upstream version 2.8.16 of branch 2.8.
Fixed critical bug list:
- mjson: fix possible DoS when parsing numbers
Fixed major bug list:
- listeners: transfer connection accounting when switching listeners
Fixed medium bugs list:
- check: Requeue healthchecks on I/O events to handle check timeout
- check: Set SOCKERR by default when a connection error is reported
- checks: fix ALPN inheritance from server
- dns: Reset reconnect tempo when connection is finally established
- fd: Use the provided tgid in fd_insert() to get tgroup_info
- h1: Allow reception if we have early data
- h1/h2/h3: reject forbidden chars in the Host header field
- h2/h3: reject some forbidden chars in :authority before reassembly
- hlua: Add function to change the body length of an HTTP Message
- hlua: Forbid any L6/L7 sample fetche functions from lua services
- hlua: Report to SC when data were consumed on a lua socket
-...
- https://bugs.mageia.org/show_bug.cgi?id=34673
- https://www.haproxy.org/download/2.8/src/CHANGELOG
- https://www.haproxy.com/blog/october-2025-cve-2025-11230-haproxy-mjson-library-denial-of-service-vulnerability
- https://www.cve.org/CVERecord?id=CVE-2025-11230
- 9/core/haproxy-2.8.16-1.mga9
Get the latest Linux and open source security news straight to your inbox.