DEBIAN-CVE-2026-40394

Source
https://security-tracker.debian.org/tracker/CVE-2026-40394
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40394.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-40394
Upstream
  • CVE-2026-40394
Withdrawn
2026-05-09T02:00:42Z
Published
2026-04-12T20:16:17Z
Modified
2026-05-09T02:00:42Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Varnish Cache 9 before 9.0.1 and Varnish Enterprise before 6.0.16r11 allows a "workspace overflow" denial of service (daemon panic) for certain amounts of prefetched data. The setup of an HTTP/2 session starts with a speculative HTTP/1 transport, and upon upgrading to h2 the HTTP/1 request is repurposed as stream zero. During the upgrade, a buffer allocation is made to reserve space to send frames to the client. This allocation would split the original workspace, and depending on the amount of prefetched data, the next fetch could perform a pipelining operation that would run out of workspace.

References

Affected packages

Debian:11 / varnish

Package

Name
varnish
Purl
pkg:deb/debian/varnish?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.5.1-1
6.5.1-1+deb11u1
6.5.1-1+deb11u2
6.5.1-1+deb11u3
6.5.1-1+deb11u4
6.5.1-1+deb11u5
6.5.2-1
6.6.1-1
7.*
7.1.0-4
7.1.0-5
7.1.0-6
7.1.1-1
7.1.1-1.1
7.1.1-1.2
7.5.0-1
7.5.0-2
7.5.0-3
7.6.0-1
7.6.0-2
7.6.1-1
7.6.1-2
7.7.0-1
7.7.0-2
7.7.0-3
7.7.1-1
7.7.2-1
7.7.2-2
7.7.3-1
7.7.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40394.json"

Debian:12 / varnish

Package

Name
varnish
Purl
pkg:deb/debian/varnish?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.1.1-1.1
7.1.1-1.1+deb12u1
7.1.1-1.2
7.1.1-2+deb12u1
7.5.0-1
7.5.0-2
7.5.0-3
7.6.0-1
7.6.0-2
7.6.1-1
7.6.1-2
7.7.0-1
7.7.0-2
7.7.0-3
7.7.1-1
7.7.2-1
7.7.2-2
7.7.3-1
7.7.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40394.json"

Debian:13 / varnish

Package

Name
varnish
Purl
pkg:deb/debian/varnish?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.7.0-3
7.7.1-1
7.7.2-1
7.7.2-2
7.7.3-1
7.7.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40394.json"

Debian:14 / varnish

Package

Name
varnish
Purl
pkg:deb/debian/varnish?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

7.*
7.7.0-3
7.7.1-1
7.7.2-1
7.7.2-2
7.7.3-1
7.7.3-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-40394.json"