Описание
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
A flaw was found in httpd. An integer overflow in the mod_dav_fs module occurs when processing Web Distributed Authoring and Versioning (WebDAV) PROPPATCH requests that declare an excessive number of XML namespaces. An authenticated remote attacker with write access can exploit this flaw to crash server worker processes, causing a Denial of Service (DoS), and persistently corrupt the directory's property database.
Меры по смягчению последствий
If WebDAV capabilities are not required, disable the mod_dav_fs module:
- Comment out the
dav_fs_moduledirective in/etc/httpd/conf.modules.d/00-dav.conf:
Alternatively, if WebDAV is required but property modifications can be restricted, block the PROPPATCH method in the affected <Directory> or <Location> configuration block:
- Apply the configuration changes:
Caveats:
Disabling mod_dav_fs disables file-backed WebDAV shares across the server. Blocking PROPPATCH prevents clients from manipulating WebDAV dead properties.
Warning: Reloading or restarting the httpd service will temporarily impact active client connections.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | httpd | Affected | ||
| Red Hat Enterprise Linux 6 | httpd | Out of support scope | ||
| Red Hat Enterprise Linux 7 | httpd | Affected | ||
| Red Hat Enterprise Linux 8 | httpd:2.4/httpd | Affected | ||
| Red Hat Enterprise Linux 9 | httpd | Affected | ||
| Red Hat Hardened Images | httpd-main-2.4.69-1.hum1 | Fixed | RHSA-2026:74858 | 02.10.2026 |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
Связанные уязвимости
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 al ...
Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.
5.4 Medium
CVSS3