stable

trafficserver-9.2.13-1.el9

FEDORA-EPEL-2026-7d17b6d554 created by jered 5 months ago for Fedora EPEL 9

Resolves: CVE-2025-58136 - A simple legitimate POST request causes a crash CVE-2025-65114 - Malformed chunked message body allows request smuggling

Changes with Apache Traffic Server 9.2.13 #12834 - Make 9.2.x buildable on macOS 26 #12909 - Updating make/configure for hdrrwr lib includes #13038 - 9.2.x: Fix prev_is_cr flag handling in chunked encoding parser #13039 - 9.2.x: HttpSM - make sure we have a valid buffer to write on.

This update has been submitted for testing by jered.

5 months ago

This update's test gating status has been changed to 'ignored'.

5 months ago

jered edited this update.

5 months ago

This update has been pushed to testing.

5 months ago

jered edited this update.

5 months ago

This update has been submitted for stable by bodhi.

5 months ago

This update has been pushed to stable.

5 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
7 days
Dates
submitted
5 months ago
in testing
5 months ago
in stable
5 months ago
modified
5 months ago
approved
5 months ago
BZ#2454963 CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [epel-all]
0
0
BZ#2454964 CVE-2025-65114 trafficserver: Apache Traffic Server: Request smuggling due to malformed chunked messages [epel-all]
0
0

Automated Test Results