Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29169

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

A flaw was found in the mod_dav_lock module of httpd. This vulnerability allows a remote unauthenticated attacker to crash the server due to a NULL pointer dereference via a specially crafted request.

Отчет

This issue allows an unauthenticated remote attacker to crash the server via a specially crafted request. However, the mod_dav_lock module is obsolete and rarely enabled in modern environments. The only known use-case for the module was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Due to this reason, this vulnerability has been rated with a low severity. This flaw only affects configurations with mod_dav_lock loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

Меры по смягчению последствий

Disabling mod_dav_lock and restarting httpd will mitigate this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:3410901.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporthttpdFixedRHSA-2026:4704628.07.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:4282821.07.2026
Red Hat Enterprise Linux 9httpdFixedRHSA-2026:4190620.07.2026
Red Hat JBoss Core Services 2.4.62.SP4mod_dav_lock.soFixedRHSA-2026:2720122.06.2026
Red Hat Hardened Imageshttpd-main-2.4.67-1.hum1FixedRHSA-2026:1708013.05.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2465296httpd: NULL pointer dereference via specially crafted request

EPSS

Процентиль: 45%
0.00594
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

CVSS3: 7.5
nvd
3 месяца назад

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

CVSS3: 7.5
msrc
3 месяца назад

Apache HTTP Server: mod_dav_lock indirect lock crash

CVSS3: 7.5
debian
3 месяца назад

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.6 ...

CVSS3: 7.5
github
3 месяца назад

A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.

EPSS

Процентиль: 45%
0.00594
Низкий

7.5 High

CVSS3