Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ SUSE-SU-2025:20230-1 — haproxy (CVE-2024-53008)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for haproxy

This update for haproxy fixes the following issues:

Update to version 2.8.11+git0.01c1056a4:

  • VUL-0: CVE-2024-53008: haproxy: HTTP/3 request smuggling via malformed HTTP headers forwarded to a HTTP/1.1 non-compliant back-end server (bsc#1233973)
  • BUG/MINOR: cfgparse-listen: fix option httpslog override warning message
  • BUG/MEDIUM: promex: Wait to have the request before sending the response
  • BUG/MEDIUM: cache/stats: Wait to have the request before sending the response
  • BUG/MEDIUM: queue: implement a flag to check for the dequeuing
  • BUG/MINOR: clock: validate that now_offset still applies to the current date
  • BUG/MINOR: clock: make time jump corrections a bit more accurate
  • BUG/MINOR: polling: fix time reporting when using busy polling
  • BUG/MAJOR: mux-h1: Wake SC to perform 0-copy forwarding in CLOSING state
  • BUG/MEDIUM: pattern: prevent UAF on reused pattern expr
  • BUG/MINOR: pattern: prevent const sample from being tampered in pat_match_beg()
  • BUG/MEDIUM: clock: detect and cover jumps during execution
  • REGTESTS: fix random failures with wrong_ip_port_logging.vtc under load
  • DOC: configuration: place the HAPROXY_HTTP_LOG_FMT example on the correct line
  • BUG/MINOR: pattern: do not leave a leading comma on "set" error messages
  • BUG/MINOR: pattern: pat_ref_set: return 0 if err was found
  • BUG/MINOR: pattern: pat_ref_set: fix UAF reported by coverity
  • BUG/MINOR: stconn: Request to send something to be woken up when the pipe is full
  • BUG/MEDIUM: mux-pt/mux-h1: Release the pipe on connection error on sending path
  • BUG/MEDIUM: clock: also update the date offset on time jumps
  • DOC: config: correct the table for option tcplog
  • BUG/MINOR: h3: properly reject too long header responses
  • BUG/MINOR: proto_uxst: delete fd from fdtab if listen() fails
  • BUG/MINOR: mux-quic: do not send too big MAX_STREAMS ID
  • REGTESTS: mcli: test the pipelined commands on master CLI
  • BUG/MEDIUM: mworker/cli: fix pipelined modes on master CLI
  • MINOR: channel: implement ci_insert() function
  • BUG/MINOR: proto_tcp: keep error msg if listen() fails
  • BUG/MINOR: proto_tcp: delete fd from fdtab if listen() fails
  • BUG/MINOR: quic/trace: make quic_conn_enc_level_init() emit NEW not CLOSE
  • BUG/MINOR: trace/quic: make "qconn" selectable as a lockon criterion
  • BUG/MINOR: trace: automatically start in waiting mode with "start <evt>"
  • BUG/MEDIUM: trace: fix null deref in lockon mechanism since TRACE_ENABLED()
  • BUG/MINOR: trace/quic: permit to lock on frontend/connect/session etc
  • BUG/MINOR: trace/quic: enable conn/session pointer recovery from quic_conn
  • BUG/MINOR: fcgi-app: handle a possible strdup() failure
  • BUG/MEDIUM: mux-h2: Propagate term flags to SE on error in h2s_wake_one_stream
  • BUG/MEDIUM: h2: Only report early HTX EOM for tunneled streams
  • BUG/MEDIUM: http-ana: Report error on write error waiting for the response
  • BUG/MEDIUM: quic: prevent conn freeze on 0RTT undeciphered content
  • BUG/MEDIUM: stconn: Report error on SC on send if a previous SE error was set
  • BUG/MEDIUM: mux-h1: Properly handle empty message when an error is triggered
  • BUG/MEDIUM: cli: Always release back endpoint between two commands on the mcli
  • BUG/MEDIUM: stream: Prevent mux upgrades if client connection is no longer ready
  • BUG/MEDIUM: init: fix fd_hard_limit default in compute_ideal_maxconn
  • MEDIUM: init: set default for fd_hard_limit via DEFAULT_MAXFD (take #2)
  • BUG/MEDIUM: queue: deal with a rare TOCTOU in assign_server_and_queue()
  • MINOR: queue: add a function to check for TOCTOU after queueing
  • BUG/MEDIUM: jwt: Clear SSL error queue on error when checking the signature
  • BUG/MINOR: quic: Lack of precision when computing K (cubic only cc)
  • BUG/MINOR: cli: Atomically inc the global request counter between CLI commands
  • BUG/MINOR: server: Don't warn fallback IP is used during init-addr resolution
  • BUG/MINOR: stick-table: fix crash for src_inc_gpc() without stkcounter
  • DOC: config: improve the http-keep-alive section
  • DOC: configuration: issuers-chain-path not compatible with OCSP
  • BUG/MEDIUM: ssl_sock: fix deadlock in ssl_sock_load_ocsp() on error path
  • BUG/MEDIUM: debug/cli: fix "show threads" crashing with low thread counts
  • BUG/MINOR: session: Eval L4/L5 rules defined in the default section
  • BUG/MEDIUM: bwlim: Be sure to never set the analyze expiration date in past
  • BUG/MEDIUM: spoe: Be sure to create a SPOE applet if none on the current thread
  • BUG/MEDIUM: h1: Reject empty Transfer-encoding header
  • BUG/MINOR: h1: Reject empty coding name as last transfer-encoding value
  • BUG/MINOR: h1: Fail to parse empty transfer coding names
  • BUG/MINOR: jwt: fix variable initialisation
  • DOC: configuration: update maxconn description
  • BUG/MINOR: jwt: don't try to load files with HMAC algorithm
  • MEDIUM: ssl: initialize the SSL stack explicitely
  • DOC: config

Affected software

SUSE-SU-2025:20230-1 is recorded against 1 package.

  • haproxy (fixed in 2.8.11+git0.01c1056a4-slfo.1.1_1.1)

Timeline and source

Published on 5 March 2025 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-03-05
Updated 2026-08-20
Modified 2026-03-23
Fix URL N/A

Affected Packages

Software From version Fixed in
haproxy 2.8.11+git0.01c1056a4-slfo.1.1_1.1

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:20230-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:20230-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.