Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33007

Опубликовано: 04 мая 2026
Источник: redhat
CVSS3: 5.3

Описание

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

A flaw was found in the mod_authn_socache module of httpd. This vulnerability allows an unauthenticated remote user to crash a child process due to a NULL pointer dereference when the server is operating in a caching forward proxy configuration.

Отчет

This issue allows an unauthenticated remote attacker to cause a crash in a child process. However, the main parent process remains active and functional. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_authn_socache loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.

Меры по смягчению последствий

Disabling mod_authn_socache and restarting httpd will mitigate this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdAffected
Red Hat Enterprise Linux 7httpdAffected
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
JBoss Core Services on RHEL 7jbcs-httpd24-httpdFixedRHSA-2026:2720022.06.2026
Red Hat Enterprise Linux 10httpdFixedRHSA-2026:2143327.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupporthttpdFixedRHSA-2026:4704628.07.2026
Red Hat Enterprise Linux 8httpdFixedRHSA-2026:2214001.06.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnhttpdFixedRHSA-2026:3684608.07.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupporthttpdFixedRHSA-2026:3683108.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2465299httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVSS3: 5.3
nvd
3 месяца назад

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

CVSS3: 5.3
msrc
3 месяца назад

Apache HTTP Server: mod_authn_socache crash

CVSS3: 5.3
debian
3 месяца назад

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Ser ...

CVSS3: 5.3
github
3 месяца назад

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

5.3 Medium

CVSS3

Уязвимость CVE-2026-33007