Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-55753

Опубликовано: 05 дек. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

An integer overflow flaw has been discovered in the Apache HTTP server. The integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdNot affected
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2026:299423.02.2026
JBoss Core Services on RHEL 7jbcs-httpd24-mod_mdFixedRHSA-2026:299423.02.2026
Red Hat Enterprise Linux 10mod_mdFixedRHSA-2025:2373822.12.2025
Red Hat Enterprise Linux 10.0 Extended Update Supportmod_mdFixedRHSA-2026:009306.01.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2025:2373222.12.2025
Red Hat Enterprise Linux 8.2 Advanced Update SupporthttpdFixedRHSA-2026:000905.01.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:001005.01.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnhttpdFixedRHSA-2026:001005.01.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2419140mod_md: Apache HTTP Server: mod_md (ACME), unintended retry intervals

EPSS

Процентиль: 22%
0.00072
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
nvd
4 месяца назад

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.

CVSS3: 7.5
msrc
4 месяца назад

Apache HTTP Server: mod_md (ACME), unintended retry intervals

CVSS3: 7.5
debian
4 месяца назад

An integer overflow in the case of failed ACME certificate renewal lea ...

rocky
3 месяца назад

Important: mod_md security update

EPSS

Процентиль: 22%
0.00072
Низкий

7.5 High

CVSS3