{"id":"UBUNTU-CVE-2023-26964","details":"An issue was discovered in hyper v0.13.7. h2-0.2.4 Stream stacking occurs when the H2 component processes HTTP2 RST_STREAM frames. As a result, the memory and CPU usage are high which can lead to a Denial of Service (DoS).","modified":"2026-05-20T16:07:35.990014633Z","published":"2023-04-11T14:15:00Z","upstream":["CVE-2023-26964"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-26964"},{"type":"REPORT","url":"https://github.com/hyperium/hyper/issues/2877"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2023-26964"}],"affected":[{"package":{"name":"rust-hyper","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/rust-hyper?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.12.35-1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.12.35-1","binary_name":"librust-hyper+default-dev"},{"binary_name":"librust-hyper+futures-cpupool-dev","binary_version":"0.12.35-1"},{"binary_name":"librust-hyper+net2-dev","binary_version":"0.12.35-1"},{"binary_version":"0.12.35-1","binary_name":"librust-hyper+runtime-dev"},{"binary_name":"librust-hyper+tokio-dev","binary_version":"0.12.35-1"},{"binary_name":"librust-hyper+tokio-executor-dev","binary_version":"0.12.35-1"},{"binary_version":"0.12.35-1","binary_name":"librust-hyper+tokio-reactor-dev"},{"binary_name":"librust-hyper+tokio-tcp-dev","binary_version":"0.12.35-1"},{"binary_version":"0.12.35-1","binary_name":"librust-hyper+tokio-threadpool-dev"},{"binary_name":"librust-hyper+tokio-timer-dev","binary_version":"0.12.35-1"},{"binary_name":"librust-hyper-dev","binary_version":"0.12.35-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26964.json"}},{"package":{"name":"rust-hyper","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/rust-hyper?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.14.25-1","0.14.27-1"],"ecosystem_specific":{"binaries":[{"binary_name":"librust-hyper-dev","binary_version":"0.14.27-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26964.json"}},{"package":{"name":"rust-hyper","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/rust-hyper?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.2-1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.5.2-1","binary_name":"librust-hyper-dev"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26964.json"}},{"package":{"name":"rust-hyper","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/rust-hyper?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.5.2-1","1.7.0-1","1.8.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"librust-hyper-dev","binary_version":"1.8.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2023/UBUNTU-CVE-2023-26964.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}