CVE-2023-44487 impact

From Yocto Project
Revision as of 12:41, 11 October 2023 by Marta Rybczynska (talk | contribs) (Initial version)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigationJump to search

(WIP) CVE-2023-44487 (HTTP2 RapidReset issue)

This is a synchronization wiki page to coordinate work on CVE-2023-44487 (known as HTTP/2 Rapid Reset issue) impact in the Yocto Project. When you have new information, do not hesitate to update/add to this page.

OE-core

  • go

Status: Affected, confirmed Master version: 1.20.7 (affected), update needed to 1.20.10 by Jose Quaresma Nanbield version: Under analysis Kirkstone version: Under analysis Dunfell version: Under analysis

Sources: https://go.dev/doc/devel/release#go1.20

meta-openembedded

Under analysis