Linuxsecurity
Denial of Service Vulnerability in Fedora's erlang-cowboy and cowlib
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A coordinated security update was released for Fedora 43 and 44 addressing CVE-2026-59248, a denial of service vulnerability in the erlang-cowboy and cowlib libraries. This vulnerability stems from unbounded HPACK/QPACK prefixed-integer decoding, which could lead to service disruption. The updates were released upstream on 2026-07-27, with affected versions being cowlib 2.19.0 and cowboy 2.18.0. Key fixes include rejecting empty HTTP/2 CONTINUATION frames and limiting cookie parsing. Users are advised to upgrade their systems using the dnf update program. The vulnerability was published on 2026-07-28, and both Fedora 43 and 44 are impacted. The updates are crucial for maintaining system integrity and availability.
Key Points: • CVE-2026-59248 affects Fedora 43 and 44 due to a denial of service vulnerability. • The vulnerability is linked to unbounded HPACK/QPACK decoding in erlang-cowboy and cowlib. • Users are urged to apply the security updates released on 2026-07-27 immediately.