Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Mageia 9 Haproxy Critical DoS Vulnerability MGASA-2025-0242 CVE-2025-11230

mageia
Calendar Grey October 22, 2025
Dist Mageia Esm H88
Updated haproxy packages in Mageia address critical DoS vulnerabilities and bugs with fixes in version 2.8.16.
MGASA-2025-0242 - Updated haproxy packages fix security vulnerability & bugs

Summary

Description: Haproxy has a critical, a major, few medium and few minor bugs fixed in the last upstream version 2.8.16 of branch 2.8.
Fixed critical bug list: - mjson: fix possible DoS when parsing numbers
Fixed major bug list: - listeners: transfer connection accounting when switching listeners
Fixed medium bugs list: - check: Requeue healthchecks on I/O events to handle check timeout - check: Set SOCKERR by default when a connection error is reported - checks: fix ALPN inheritance from server - dns: Reset reconnect tempo when connection is finally established - fd: Use the provided tgid in fd_insert() to get tgroup_info - h1: Allow reception if we have early data - h1/h2/h3: reject forbidden chars in the Host header field - h2/h3: reject some forbidden chars in :authority before reassembly - hlua: Add function to change the body length of an HTTP Message - hlua: Forbid any L6/L7 sample fetche functions from lua services - hlua: Report to SC when data were consumed on a lua socket -...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=34673

- https://www.haproxy.org/download/2.8/src/CHANGELOG

- https://www.haproxy.com/blog/october-2025-cve-2025-11230-haproxy-mjson-library-denial-of-service-vulnerability

- https://www.cve.org/CVERecord?id=CVE-2025-11230

Resolution

SRPMS

- 9/core/haproxy-2.8.16-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 22 Oct 2025
URL: https://advisories.mageia.org/MGASA-2025-0242.html
Type: security
CVE: CVE-2025-11230

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here