Описание
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server.
This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63.
Users are recommended to upgrade to version 2.4.64, which fixes the issue.
A flaw was found in Apache HTTP Server. This late release of memory after effective lifetime vulnerability allows a remote, unauthenticated attacker to cause a denial of service (DoS). The vulnerability can lead to resource exhaustion, making the server unavailable to legitimate users.
Меры по смягчению последствий
The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to:
- Remove h2 and h2c from the Protocols directive
- Disable mod_http2 and mod_proxy_http2 modules (if not required) https://access.redhat.com/node/7056356
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Not affected | ||
| Red Hat Enterprise Linux 7 | httpd | Not affected | ||
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2 | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2 | Fixed | RHSA-2026:27200 | 22.06.2026 |
| Red Hat Enterprise Linux 10 | mod_http2 | Fixed | RHSA-2026:22528 | 03.06.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:22140 | 01.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Late Release of Memory after Effective Lifetime vulnerability in Apach ...
EPSS
5.3 Medium
CVSS3