Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48913

Опубликовано: 08 июн. 2026
Источник: redhat
CVSS3: 7.3

Описание

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

A flaw was found in the Apache HTTP Server's mod_http2 module. This vulnerability, known as a Use After Free, occurs when the server's file handles are exhausted. An attacker could potentially exploit this to cause a denial of service or, in some cases, execute arbitrary code, leading to system compromise.

Отчет

A use-after-free vulnerability exists in the Apache HTTP Server mod_http2 module when system file handles are exhausted. A remote attacker could trigger this flaw via HTTP/2 requests to cause a denial of service (crash) or memory corruption.

Меры по смягчению последствий

To mitigate this issue, disable the mod_http2 module if HTTP/2 protocol support is not required. This can be achieved by commenting out or removing the LoadModule http2_module modules/mod_http2.so line in the Apache HTTP Server configuration file (e.g., /etc/httpd/conf.modules.d/00-base.conf or similar). After modifying the configuration, the httpd service must be restarted for the changes to take effect. This action may impact services relying on HTTP/2.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdFix deferred
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat Enterprise Linux 8httpd:2.4/httpdFix deferred
Red Hat Enterprise Linux 8mod_http2Affected
Red Hat Enterprise Linux 9httpdFix deferred
Red Hat Enterprise Linux 9mod_http2Affected
Red Hat JBoss Core Servicesjbcs-httpd24-mod_http2Affected
Red Hat JBoss Core Servicesmod_http2.soAffected
Red Hat Enterprise Linux 10mod_http2FixedRHSA-2026:3435501.07.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2486405httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
около 2 месяцев назад

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

CVSS3: 7.3
nvd
около 2 месяцев назад

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

msrc
около 2 месяцев назад

Apache HTTP Server: mod_http2 memory corruption when file handles exhausted

CVSS3: 7.3
debian
около 2 месяцев назад

Use After Free vulnerability in Apache HTTP Server module mod_http2 wh ...

CVSS3: 7.3
github
около 2 месяцев назад

Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

7.3 High

CVSS3

Уязвимость CVE-2026-48913