Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97542.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97542
Upstream
  • CVE-2022-4996
Published
2026-08-20T00:16:50Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2022-4996 affecting package nghttp2 1.61.0-3
Details

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point comparison with incorrect operator. It is possible to launch the attack remotely. The exploit has been published and may be used. It is best practice to apply a patch to resolve this issue.

References

Affected packages

Azure Linux:3 / nghttp2

Package

Name
nghttp2
Purl
pkg:rpm/azure-linux/nghttp2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.61.0-3

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97542.json"