The idle stream handling in nghttp2 before 1.6.0 allows attackers to have unspecified impact via unknown vectors, aka a heap-use-after-free bug.
{
"binaries": [
{
"binary_name": "libnghttp2-14",
"binary_version": "1.7.1-1"
},
{
"binary_name": "libnghttp2-14-dbgsym",
"binary_version": "1.7.1-1"
},
{
"binary_name": "libnghttp2-dev",
"binary_version": "1.7.1-1"
},
{
"binary_name": "libnghttp2-doc",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2-client",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2-client-dbgsym",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2-proxy",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2-proxy-dbgsym",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2-server",
"binary_version": "1.7.1-1"
},
{
"binary_name": "nghttp2-server-dbgsym",
"binary_version": "1.7.1-1"
}
],
"availability": "No subscription required"
}