Описание
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration.
Users are recommended to upgrade to version 2.4.67, which fixes this issue.
A flaw was found in the mod_authn_socache module of httpd. This vulnerability allows an unauthenticated remote user to crash a child process due to a NULL pointer dereference when the server is operating in a caching forward proxy configuration.
Отчет
This issue allows an unauthenticated remote attacker to cause a crash in a child process. However, the main parent process remains active and functional. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_authn_socache loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.
Меры по смягчению последствий
Disabling mod_authn_socache and restarting httpd will mitigate this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:21433 | 27.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | httpd | Fixed | RHSA-2026:47046 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:22140 | 01.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36831 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
5.3 Medium
CVSS3
Связанные уязвимости
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Ser ...
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
5.3 Medium
CVSS3