Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
H2O could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7892-1 November 26, 2025 h2o vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: H2O could be made to crash if it received specially crafted network traffic. Software Description: - h2o: the optimized HTTP/1, HTTP/2 server Details: It was discovered that H2O exhibited poor server resource management in its HTTP/2 protocol. An attacker could possibly use this issue to cause H2O to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS h2o 2.2.5+dfsg2-6.1ubuntu2+esm1 Available with Ubuntu Pro libh2o0.13 2.2.5+dfsg2-6.1ubuntu2+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS h2o 2.2.5+dfsg2-3ubuntu0.1~esm1 Available with Ubuntu Pro libh2o0.13 2.2.5+dfsg2-3ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7892-1 CVE-2023-44487 . H2O crash issue in Ubuntu releases identified, requiring immediate patches for critical denial of service vulnerabilities.. H2O Security, Ubuntu 22.04, Denial of Service, H2O HTTP Server, Ubuntu LTS Security. . Severity: Critical. LinuxSecurity.com Team
A vulnerability has been identified in h2o, a high-performance web server with support for HTTP/2. A security vulnerability CVE-2023-44487 was discovered that could potentially . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3638-1
Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service. For the stable distribution (buster), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4508-1
Get the latest Linux and open source security news straight to your inbox.