haproxy-1.8.27-5.el8_10.2

エラータID: AXSA:2026-1575:02

Release date: 
Wednesday, August 19, 2026 - 16:03
Subject: 
haproxy-1.8.27-5.el8_10.2
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The haproxy packages provide a reliable, high-performance network load balancer for TCP and HTTP-based applications.

Security Fix(es):

* haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions (CVE-2026-55204)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-55204
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. haproxy-1.8.27-5.el8_10.2.src.rpm
    MD5: 1f2bc5e1b5afaa3069a4266dabadc6a0
    SHA-256: 7e220f329263f60c26afe00b49945cad9176e54e1fcc586884c08fc4a953b46e
    Size: 2.15 MB

Asianux Server 8 for x86_64
  1. haproxy-1.8.27-5.el8_10.2.x86_64.rpm
    MD5: 159a21eaea9af45b8d3b291d59dbeb23
    SHA-256: 0750d7bfb72b1109f943a23504f2d7942141140acf191dce68b314ea5a02515c
    Size: 1.42 MB