Описание
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data.
This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
A flaw was found in the mod_md module of httpd. When processing OCSP (Online Certificate Status Protocol) responses from a malicious or compromised OCSP responder, the module fails to enforce proper size limits on the incoming data. This issue leads to memory exhaustion and a denial of service.
Отчет
To exploit this flaw, the Apache HTTP Server must query an untrusted or compromised OCSP responder, limiting its exposure. Due to this reason, this vulnerability has been rated with a moderate severity. This flaw only affects configurations with mod_md loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.
Меры по смягчению последствий
Disabling mod_md and restarting httpd will mitigate this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | httpd:2.4/mod_md | Affected | ||
| Red Hat Enterprise Linux 8 | mod_md | Not affected | ||
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md | Fixed | RHSA-2026:27200 | 22.06.2026 |
| Red Hat Enterprise Linux 10 | mod_md | Fixed | RHSA-2026:30845 | 29.06.2026 |
| Red Hat Enterprise Linux 9 | mod_md | Fixed | RHSA-2026:30844 | 29.06.2026 |
| Red Hat JBoss Core Services 2.4.62.SP4 | jbcs-httpd24-mod_md | Fixed | RHSA-2026:27201 | 22.06.2026 |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in Apache HTTP Server's mod_md via OCSP response data. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in ...
7.5 High
CVSS3