UBUNTU-CVE-2026-44453

Source
https://ubuntu.com/security/CVE-2026-44453
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44453.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-44453
Upstream
Published
2026-07-17T00:00:00Z
Modified
2026-07-17T14:30:46.833281165Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca. The maximum size of the memory allocated using alloca can be as huge as ~600KB, which exceeds the default pthread stack size used by musl libc (128KB). If the amount of memory allocated by alloca exceeds the stack size, the h2o server crashes with a segmentation fault, while it tries to touch the guard page. This issue has been fixed by commit 6b5370d.

References

Affected packages

Ubuntu:Pro:18.04:LTS / h2o

Package

Name
h2o
Purl
pkg:deb/ubuntu/h2o?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.3+dfsg-2
2.2.4+dfsg-1
2.2.4+dfsg-1build1
2.2.4+dfsg-1ubuntu0.1~esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
            "binary_name": "h2o"
        },
        {
            "binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
            "binary_name": "libh2o-dev-common"
        },
        {
            "binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
            "binary_name": "libh2o-evloop0.13"
        },
        {
            "binary_version": "2.2.4+dfsg-1ubuntu0.1~esm2",
            "binary_name": "libh2o0.13"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44453.json"

Ubuntu:Pro:20.04:LTS / h2o

Package

Name
h2o
Purl
pkg:deb/ubuntu/h2o?arch=source&distro=esm-apps%2Ffocal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.5+dfsg2-3
2.2.5+dfsg2-3build1
2.2.5+dfsg2-3ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.2.5+dfsg2-3ubuntu0.1~esm1",
            "binary_name": "h2o"
        },
        {
            "binary_version": "2.2.5+dfsg2-3ubuntu0.1~esm1",
            "binary_name": "libh2o-dev-common"
        },
        {
            "binary_version": "2.2.5+dfsg2-3ubuntu0.1~esm1",
            "binary_name": "libh2o-evloop0.13"
        },
        {
            "binary_version": "2.2.5+dfsg2-3ubuntu0.1~esm1",
            "binary_name": "libh2o0.13"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44453.json"

Ubuntu:Pro:22.04:LTS / h2o

Package

Name
h2o
Purl
pkg:deb/ubuntu/h2o?arch=source&distro=esm-apps%2Fjammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.5+dfsg2-6
2.2.5+dfsg2-6.1
2.2.5+dfsg2-6.1ubuntu1
2.2.5+dfsg2-6.1ubuntu2
2.2.5+dfsg2-6.1ubuntu2+esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.2.5+dfsg2-6.1ubuntu2+esm1",
            "binary_name": "h2o"
        },
        {
            "binary_version": "2.2.5+dfsg2-6.1ubuntu2+esm1",
            "binary_name": "libh2o-dev-common"
        },
        {
            "binary_version": "2.2.5+dfsg2-6.1ubuntu2+esm1",
            "binary_name": "libh2o-evloop0.13"
        },
        {
            "binary_version": "2.2.5+dfsg2-6.1ubuntu2+esm1",
            "binary_name": "libh2o0.13"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44453.json"

Ubuntu:24.04:LTS / h2o

Package

Name
h2o
Purl
pkg:deb/ubuntu/h2o?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.5+dfsg2-7
2.2.5+dfsg2-8
2.2.5+dfsg2-8.1ubuntu1
2.2.5+dfsg2-8.1ubuntu2
2.2.5+dfsg2-8.1ubuntu3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.2.5+dfsg2-8.1ubuntu3",
            "binary_name": "h2o"
        },
        {
            "binary_version": "2.2.5+dfsg2-8.1ubuntu3",
            "binary_name": "libh2o-dev-common"
        },
        {
            "binary_version": "2.2.5+dfsg2-8.1ubuntu3",
            "binary_name": "libh2o-evloop0.13t64"
        },
        {
            "binary_version": "2.2.5+dfsg2-8.1ubuntu3",
            "binary_name": "libh2o0.13t64"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44453.json"

Ubuntu:Pro:24.04:LTS / dnsdist

Package

Name
dnsdist
Purl
pkg:deb/ubuntu/dnsdist?arch=source&distro=esm-apps%2Fnoble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.0-1
1.8.2-1
1.8.2-2
1.8.2-3
1.8.3-1
1.8.3-2
1.8.3-2build1
1.8.3-2build2
1.8.3-2ubuntu0.1~esm1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1.8.3-2ubuntu0.1~esm1",
            "binary_name": "dnsdist"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-44453.json"