{"type":"TYPE_SECURITY","shortCode":"RL","name":"RLSA-2024:1690","synopsis":"Important: varnish security update","severity":"SEVERITY_IMPORTANT","topic":"An update is available for module.varnish, varnish-modules, varnish, module.varnish-modules.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list","description":"Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up.\n\nSecurity Fix(es):\n\n* varnish: HTTP\/2 Broken Window Attack may result in denial of service (CVE-2024-30156)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","solution":null,"affectedProducts":["Rocky Linux 8"],"fixes":[{"ticket":"2271486","sourceBy":"Red Hat","sourceLink":"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=2271486","description":""}],"cves":[{"name":"CVE-2024-30156","sourceBy":"MITRE","sourceLink":"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2024-30156","cvss3ScoringVector":"UNKNOWN","cvss3BaseScore":"UNKNOWN","cwe":"UNKNOWN"}],"references":[],"publishedAt":"2024-05-06T13:04:21.002456Z","rpms":{"Rocky Linux 8":{"nvras":["varnish-0:6.0.13-1.module+el8.9.0+1777+0acf9965.aarch64.rpm","varnish-0:6.0.13-1.module+el8.9.0+1777+0acf9965.src.rpm","varnish-0:6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm","varnish-devel-0:6.0.13-1.module+el8.9.0+1777+0acf9965.aarch64.rpm","varnish-devel-0:6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm","varnish-docs-0:6.0.13-1.module+el8.9.0+1777+0acf9965.aarch64.rpm","varnish-docs-0:6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm","varnish-modules-0:0.15.0-6.module+el8.5.0+677+2a78a869.aarch64.rpm","varnish-modules-0:0.15.0-6.module+el8.5.0+677+2a78a869.src.rpm","varnish-modules-0:0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm","varnish-modules-debuginfo-0:0.15.0-6.module+el8.5.0+677+2a78a869.aarch64.rpm","varnish-modules-debuginfo-0:0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm","varnish-modules-debugsource-0:0.15.0-6.module+el8.5.0+677+2a78a869.aarch64.rpm","varnish-modules-debugsource-0:0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm"]}},"rebootSuggested":false,"buildReferences":[]}

Rocky Linux: RLSA-2024:1690 varnish security update Security Advisories Updates

May 6, 2024
An update is available for module.varnish, varnish-modules, varnish, module.varnish-modules. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

Summary

An update is available for module.varnish, varnish-modules, varnish, module.varnish-modules. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list


Varnish Cache is a high-performance HTTP accelerator. It stores web pages in memory so web servers don't have to create the same web page over and over again, giving the website a significant speed up. Security Fix(es): * varnish: HTTP/2 Broken Window Attack may result in denial of service (CVE-2024-30156) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

RPMs

varnish-0:6.0.13-1.module+el8.9.0+1777+0acf9965.aarch64.rpm

varnish-0:6.0.13-1.module+el8.9.0+1777+0acf9965.src.rpm

varnish-0:6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm

varnish-devel-0:6.0.13-1.module+el8.9.0+1777+0acf9965.aarch64.rpm

varnish-devel-0:6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm

varnish-docs-0:6.0.13-1.module+el8.9.0+1777+0acf9965.aarch64.rpm

varnish-docs-0:6.0.13-1.module+el8.9.0+1777+0acf9965.x86_64.rpm

varnish-modules-0:0.15.0-6.module+el8.5.0+677+2a78a869.aarch64.rpm

varnish-modules-0:0.15.0-6.module+el8.5.0+677+2a78a869.src.rpm

varnish-modules-0:0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm

varnish-modules-debuginfo-0:0.15.0-6.module+el8.5.0+677+2a78a869.aarch64.rpm

varnish-modules-debuginfo-0:0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm

varnish-modules-debugsource-0:0.15.0-6.module+el8.5.0+677+2a78a869.aarch64.rpm

varnish-modules-debugsource-0:0.15.0-6.module+el8.5.0+677+2a78a869.x86_64.rpm

References

No References

CVEs

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-30156

Severity
Name: RLSA-2024:1690
Affected Products: Rocky Linux 8

Fixes

https://bugzilla.redhat.com/show_bug.cgi?id=2271486


Related News