Описание
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
A flaw was found in the Apache HTTP Server's mod_http2 module. This vulnerability, known as a Use After Free, occurs when the server's file handles are exhausted. An attacker could potentially exploit this to cause a denial of service or, in some cases, execute arbitrary code, leading to system compromise.
Отчет
A use-after-free vulnerability exists in the Apache HTTP Server mod_http2 module when system file handles are exhausted. A remote attacker could trigger this flaw via HTTP/2 requests to cause a denial of service (crash) or memory corruption.
Меры по смягчению последствий
To mitigate this issue, disable the mod_http2 module if HTTP/2 protocol support is not required. This can be achieved by commenting out or removing the LoadModule http2_module modules/mod_http2.so line in the Apache HTTP Server configuration file (e.g., /etc/httpd/conf.modules.d/00-base.conf or similar).
After modifying the configuration, the httpd service must be restarted for the changes to take effect. This action may impact services relying on HTTP/2.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | httpd | Fix deferred | ||
| Red Hat Enterprise Linux 6 | httpd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | httpd | Out of support scope | ||
| Red Hat Enterprise Linux 8 | httpd:2.4/httpd | Fix deferred | ||
| Red Hat Enterprise Linux 8 | mod_http2 | Affected | ||
| Red Hat Enterprise Linux 9 | httpd | Fix deferred | ||
| Red Hat Enterprise Linux 9 | mod_http2 | Affected | ||
| Red Hat JBoss Core Services | jbcs-httpd24-mod_http2 | Affected | ||
| Red Hat JBoss Core Services | mod_http2.so | Affected | ||
| Red Hat Enterprise Linux 10 | mod_http2 | Fixed | RHSA-2026:34355 | 01.07.2026 |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Apache HTTP Server: mod_http2 memory corruption when file handles exhausted
Use After Free vulnerability in Apache HTTP Server module mod_http2 wh ...
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
7.3 High
CVSS3