Описание
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in Apache HTTP Server, specifically within the mod_xml2enc module. This heap-based buffer overflow vulnerability can be triggered when processing untrusted content through the xml2StartParse function. A remote attacker could potentially exploit this to cause a denial of service, information disclosure, or possibly arbitrary code execution.
Отчет
In Red Hat Enterprise Linux (RHEL), the httpd package includes mod_xml2enc, which provides encoding support for filters like mod_proxy_html. Because this flaw relies on processing unvetted or untrusted input text lengths, the impact presents a high risk to availability (Denial of Service via worker crashes) and a potential risk to confidentiality if an attacker is capable of executing remote code within the context of the apache or httpd daemon process.
Меры по смягчению последствий
To mitigate this vulnerability, disable the mod_xml2enc module if its functionality for XML internationalization is not essential. This can be done by commenting out the LoadModule xml2enc_module modules/mod_xml2enc.so directive in the Apache HTTP Server configuration. A service restart is required for the change to take effect.
Note: Disabling mod_xml2enc will cause any configurations relying heavily on mod_proxy_html or raw HTML/XML encoding conversions to function incorrectly or fail. Red Hat strongly recommends upgrading to a patched version of httpd as soon as it becomes available for your specific RHEL channel.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:34109 | 01.07.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:42828 | 21.07.2026 |
| Red Hat Enterprise Linux 9 | httpd | Fixed | RHSA-2026:41906 | 20.07.2026 |
| Red Hat Hardened Images | httpd-main-2.4.68-1.hum1 | Fixed | RHSA-2026:25042 | 10.06.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server withmod ...
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
EPSS
7.5 High
CVSS3