Bug 2490518 (CVE-2026-55204) - CVE-2026-55204 haproxy: HAProxy: Denial of Service via HPACK dynamic table insertions
Summary: CVE-2026-55204 haproxy: HAProxy: Denial of Service via HPACK dynamic table in...
Keywords:
Status: NEW
Alias: CVE-2026-55204
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2501072
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-18 17:02 UTC by OSIDB Bzimport
Modified: 2026-08-17 21:49 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:55679 0 None None None 2026-08-17 15:00:46 UTC
Red Hat Product Errata RHSA-2026:55772 0 None None None 2026-08-17 16:59:34 UTC
Red Hat Product Errata RHSA-2026:55800 0 None None None 2026-08-17 17:20:04 UTC
Red Hat Product Errata RHSA-2026:55801 0 None None None 2026-08-17 17:45:23 UTC
Red Hat Product Errata RHSA-2026:55802 0 None None None 2026-08-17 17:50:21 UTC
Red Hat Product Errata RHSA-2026:55803 0 None None None 2026-08-17 18:38:41 UTC
Red Hat Product Errata RHSA-2026:55859 0 None None None 2026-08-17 21:49:52 UTC
Red Hat Product Errata RHSA-2026:55860 0 None None None 2026-08-17 21:35:37 UTC
Red Hat Product Errata RHSA-2026:55861 0 None None None 2026-08-17 21:04:46 UTC
Red Hat Product Errata RHSA-2026:55862 0 None None None 2026-08-17 21:12:56 UTC

Description OSIDB Bzimport 2026-06-18 17:02:09 UTC
HAProxy through  3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.

Comment 4 errata-xmlrpc 2026-08-17 15:00:44 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:55679 https://access.redhat.com/errata/RHSA-2026:55679

Comment 5 errata-xmlrpc 2026-08-17 16:59:32 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:55772 https://access.redhat.com/errata/RHSA-2026:55772

Comment 6 errata-xmlrpc 2026-08-17 17:20:03 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:55800 https://access.redhat.com/errata/RHSA-2026:55800

Comment 7 errata-xmlrpc 2026-08-17 17:45:21 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:55801 https://access.redhat.com/errata/RHSA-2026:55801

Comment 8 errata-xmlrpc 2026-08-17 17:50:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:55802 https://access.redhat.com/errata/RHSA-2026:55802

Comment 9 errata-xmlrpc 2026-08-17 18:38:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:55803 https://access.redhat.com/errata/RHSA-2026:55803

Comment 10 errata-xmlrpc 2026-08-17 21:04:45 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:55861 https://access.redhat.com/errata/RHSA-2026:55861

Comment 11 errata-xmlrpc 2026-08-17 21:12:55 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:55862 https://access.redhat.com/errata/RHSA-2026:55862

Comment 12 errata-xmlrpc 2026-08-17 21:35:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:55860 https://access.redhat.com/errata/RHSA-2026:55860

Comment 13 errata-xmlrpc 2026-08-17 21:49:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:55859 https://access.redhat.com/errata/RHSA-2026:55859


Note You need to log in before you can comment on or make changes to this bug.