Hi, this is tracked in https://people.canonical.com/~ubuntu-security/cve/2019/CVE-2019-0197.html but the priority currently is low.
There seems to be all kind of http2 effort right now. I'll ping the security team to be aware of your bug to close it once a fix is released. ** Changed in: apache2 (Ubuntu) Status: New => Triaged -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1840188 Title: Apply fix for CVE-2019-0197 in v2.4.29 in Bionic and Disco To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/apache2/+bug/1840188/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs