Security Advisory: LiteSpeed Web Server HTTP/2 Request Smuggling
This is a security release for LiteSpeed. Update the product on every affected server to the patched release — there is no workaround, and unpatched servers remain exposed until updated.
Затронутые версии
LiteSpeed Web Server 6.2.5 and earlier
Исправленная версия
LiteSpeed Web Server 6.2.6
Команда обновления по умолчанию
yum update -y
Команды исправления
AlmaLinux 9 / CloudLinux 9
dnf update lsws
/usr/local/lsws/bin/lshttpd -r
AlmaLinux 8 / CloudLinux 8
dnf update lsws
/usr/local/lsws/bin/lshttpd -r
CentOS 7 / CloudLinux 7
yum update lsws
/usr/local/lsws/bin/lshttpd -r
Что это значит по лицензии SharedLicense
Your SharedLicense license itself is not affected — this is a change in LiteSpeed software, not in licensing. Update the product through its standard update channel. Licenses keep working through updates; nothing needs re-issuing or re-activating.
Источники
Предупреждения о безопасности
Похожие предупреждения
Проверьте систему на уязвимости
Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.
Проверьте свою систему