CVE-2018-14645: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
Affected products
- Canonical Ubuntu Linux: version 18.04 only
- Haproxy Haproxy: up to and including 1.8.14
- Red Hat Enterprise Linux: version 7.0 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only
- Red Hat Openshift: version 3.10 only
- Red Hat Openshift Container Platform: version 3.9 only
Published 2018-09-21. Last modified 2026-06-17.