CVE-2018-14645: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 3.1% chance of exploitation in the next 30 days.

A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.

Affected products

  • Canonical Ubuntu Linux: version 18.04 only
  • Haproxy Haproxy: up to and including 1.8.14
  • Red Hat Enterprise Linux: version 7.0 only; version 7.3 only; version 7.4 only; version 7.5 only; version 7.6 only
  • Red Hat Openshift: version 3.10 only
  • Red Hat Openshift Container Platform: version 3.9 only

Published 2018-09-21. Last modified 2026-06-17.