Post #2531687
2026-05-05 23:01 UTC
Just got an email about https://www.openwall.com/lists/oss-security/2026/05/04/19, delightful.
Patch is not yet available in Debian except unstable. To mitigate the issue (which includes potential remote code execution), run `a2dismod http2` to disable mod_http2, the source of the vulnerability. It may already be disabled.
Replies (2)
-
@ehashman@cloudisland.nz 2026-05-07 06:52
Debian packages are out now.
-
@mdione@en.osm.town 2026-05-06 10:10
@ehashman@cloudisland.nz ... and reload apache2, right?