elsa-2026-25225

oracle_linux
Description

[2.0.29-4.2] - Resolves: RHEL-188008 - address CVE-2026-43951, CVE-2026-48913 [2.0.29-4.1] - Resolves: RHEL-182410 - mod_http2: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) [2.0.29-4] - Resolves: RHEL-166269 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-49975"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.0.29-4.2]\n- Resolves: RHEL-188008 - address CVE-2026-43951, CVE-2026-48913\n\n[2.0.29-4.1]\n- Resolves: RHEL-182410 - mod_http2: HTTP/2: Remote Denial of Service via\n  compression bomb and Slowloris-style attack (CVE-2026-49975)\n\n[2.0.29-4]\n- Resolves: RHEL-166269 - httpd: Apache HTTP Server: HTTP/2 DoS by Memory\n  Increase (CVE-2025-53020)",
  "id": "ELSA-2026-25225",
  "ovalId": "oval:com.oracle.elsa:def:202625225",
  "source": "oracle_linux",
  "title": "ELSA-2026-25225:  mod_http2 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-25225.html"
}
View JSON API Download JSON