Описание
Out-of-bounds Read vulnerability in mod_proxy_ajp of
Apache HTTP Server.
This issue affects Apache HTTP Server: through 2.4.66.
Users are recommended to upgrade to version 2.4.67, which fixes the issue.
A flaw was found in the mod_proxy_ajp module of httpd. When processing AJP (Apache JServ Protocol) messages, the AJP getter functions attempt to read data beyond the allocated buffer size, allowing an attacker or a malformed request to cause an out-of-bounds read. This issue leads to a denial of service.
Отчет
To exploit this issue, the Apache HTTP Server must be configured to connect to an untrusted or compromised AJP backend server, limiting its exposure. Due to this reason, this flaw has been rated with a moderate severity. This flaw only affects configurations with mod_proxy_ajp loaded and being used. This module can be disabled via the configuration file if its functionality is not being used.
Меры по смягчению последствий
Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd | Fixed | RHSA-2026:27200 | 22.06.2026 |
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:21433 | 27.05.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | httpd | Fixed | RHSA-2026:47046 | 28.07.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:22140 | 01.06.2026 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | httpd | Fixed | RHSA-2026:36846 | 08.07.2026 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | httpd | Fixed | RHSA-2026:36831 | 08.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
Apache HTTP Server: Off-by-one OOB reads in AJP getter functions
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Ser ...
Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP Server. This issue affects Apache HTTP Server: through 2.4.66. Users are recommended to upgrade to version 2.4.67, which fixes the issue.
EPSS
7.5 High
CVSS3