Описание
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
A flaw was found in the mod_proxy_ftp module of the Apache HTTP Server. A remote attacker, by controlling a backend File Transfer Protocol (FTP) server, can trigger an infinite loop. This vulnerability, categorized as a Loop with Unreachable Exit Condition, leads to a Denial of Service (DoS) for the affected server.
Отчет
A loop with an unreachable exit condition flaw was found in the mod_proxy_ftp module of the Apache HTTP Server. A remote attacker could exploit this vulnerability by tricking the server into connecting to a malicious or compromised backend FTP server, causing the proxy_ftp_handler component to enter an infinite loop. This results in CPU exhaustion and a denial of service (DoS) condition on the affected system.
Меры по смягчению последствий
To mitigate this issue, you can disable the mod_proxy_ftp module if your environment does not require it.
Step 1: Disable the Module
Open your Apache HTTP Server configuration file (commonly located at /etc/httpd/conf.modules.d/00-proxy.conf or /etc/httpd/conf/httpd.conf) and comment out or remove the following line:
Step 2: Restart the Service
Restart the httpd service to apply the configuration changes:
Note: Disabling this module may impact applications or services that rely on Apache's FTP proxy functionality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | httpd | Affected | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd | Fixed | RHSA-2026:56868 | 19.08.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2 | Fixed | RHSA-2026:56868 | 19.08.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_jk | Fixed | RHSA-2026:56868 | 19.08.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md | Fixed | RHSA-2026:56868 | 19.08.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_proxy_cluster | Fixed | RHSA-2026:56868 | 19.08.2026 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_security | Fixed | RHSA-2026:56868 | 19.08.2026 |
| Red Hat Enterprise Linux 10 | httpd | Fixed | RHSA-2026:34109 | 01.07.2026 |
| Red Hat Enterprise Linux 8 | httpd | Fixed | RHSA-2026:42828 | 21.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.3 High
CVSS3
Связанные уязвимости
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
EPSS
7.3 High
CVSS3