Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-53020

Опубликовано: 10 июл. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

A flaw was found in Apache HTTP Server. This late release of memory after effective lifetime vulnerability allows a remote, unauthenticated attacker to cause a denial of service (DoS). The vulnerability can lead to resource exhaustion, making the server unavailable to legitimate users.

Меры по смягчению последствий

The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to:

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-mod_http2FixedRHSA-2026:2720022.06.2026
Red Hat Enterprise Linux 10mod_http2FixedRHSA-2026:2252803.06.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:2214001.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnhttpdFixedRHSA-2026:3684608.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2379343mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase

EPSS

Процентиль: 91%
0.04576
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

CVSS3: 7.5
nvd
около 1 года назад

Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.

CVSS3: 7.5
msrc
около 1 года назад

Apache HTTP Server: HTTP/2 DoS by Memory Increase

CVSS3: 7.5
debian
около 1 года назад

Late Release of Memory after Effective Lifetime vulnerability in Apach ...

rocky
около 2 месяцев назад

Moderate: mod_http2 security update

EPSS

Процентиль: 91%
0.04576
Низкий

5.3 Medium

CVSS3