Fedora Account System
Red Hat Associate
Red Hat Customer
HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing denial of service.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:55679 https://access.redhat.com/errata/RHSA-2026:55679
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:55772 https://access.redhat.com/errata/RHSA-2026:55772
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:55800 https://access.redhat.com/errata/RHSA-2026:55800
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions Via RHSA-2026:55801 https://access.redhat.com/errata/RHSA-2026:55801
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:55802 https://access.redhat.com/errata/RHSA-2026:55802
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:55803 https://access.redhat.com/errata/RHSA-2026:55803
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:55861 https://access.redhat.com/errata/RHSA-2026:55861
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On Via RHSA-2026:55862 https://access.redhat.com/errata/RHSA-2026:55862
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:55860 https://access.redhat.com/errata/RHSA-2026:55860
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:55859 https://access.redhat.com/errata/RHSA-2026:55859