Debian Rust Security Tracker 🩺🦀

RUSTSEC-2026-0258: h2 unbounded empty DATA frames

18 affected
Crate
h2
Patched Versions
>=0.4.16
Debian Version
0.4.19-1
Debian Bugs
Issued
2026-08-17
Aliases
GHSA-q83h-524g-xf6h
Patched:Affected

The h2 crate, used internally by hyper, had a flaw that would accept and queue empty DATA frames without limit. If streams were not actively drained, this could lead to unbounded memory usage, or a panic if the length overflows.

Low severity.

Patched in v0.4.16.

Affected Packages

h2 0.4.13 bmap-rs 0.2.2-1
h2 0.4.13 cargo-audit 0.22.2-1+b1
h2 0.4.13 cargo-edit 0.13.13-1
h2 0.4.13 debian-repro-status 0.4.0-2
h2 0.4.13 drt-tools 0.3.5-3
h2 0.4.13 feluda 1.15.0-2
h2 0.4.13 gpg-sq 0.13.1-14
h2 0.4.13 gpgv-sq 0.13.1-14
h2 0.4.13 ingredients 0.3.0-1
h2 0.4.13 miniserve 0.35.0-4
h2 0.4.13 ognibuild 0.2.19-2
h2 0.4.13 ripasso-cursive 0.8.0-1+b5
h2 0.4.13 ripcalc 0.4.0-1
h2 0.4.13 samply 0.13.1-1
h2 0.4.13 sequoia-git 0.6.0-2
h2 0.4.13 silver-platter 0.8.4-2+b1
h2 0.4.13 so 0.4.10-4
h2 0.4.13 xh 0.26.2-1