Advisories ยป MGAA-2024-0064

Updated haproxy package fixes some bugs

Publication date: 21 Feb 2024
Modification date: 21 Feb 2024
Type: bugfix
Affected Mageia releases : 9

Description

Haproxy has a major, few medium and few minor bugs fixed in last upstream
version 2.8.5 of branch 2.8

Fixed major bug list:
- ssl_sock: Always clear retry flags in read/write functions

Fixed medium bug list:
- cli: fix once for all the problem of missing trailing LFs
- cli: some err/warn msg dumps add LR into CSV output on stat's CLI
- h1: always reject the NUL character in header values
- h1: Don't support LF only to mark the end of a chunk size
- h3: do not crash on invalid response status code
- h3: fix incorrect snd_buf return value
- mux-h2: refine connection vs stream error on headers
- mux-h2: Report too large HEADERS frame only when rxbuf is empty
- mux-quic: report early error on stream
- ocsp: Separate refcount per instance and per store
- pool: fix rare risk of deadlock in pool_flush()
- qpack: allow 6xx..9xx status codes
- quic: fix crash on invalid qc_stream_buf_free() BUG_ON
- quic: keylog callback not called (USE_OPENSSL_COMPAT)
- quic: Possible buffer overflow when building TLS records
- quic: QUIC CID removed from tree without locking
- quic: remove unsent data from qc_stream_desc buf
- quic: Wrong K CUBIC calculation.
- spoe: Never create new spoe applet if there is no server up
- ssl: Fix crash when calling "update ssl ocsp-response" when an update is ongoing
- stats: unhandled switching rules with TCP frontend
- stconn: Allow expiration update when READ/WRITE event is pending
- stconn: Don't check pending shutdown to wake an applet up
- stconn: Forward shutdown on write timeout only if it is forwardable
                

References

SRPMS

9/core