Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-93546

Опубликовано: 01 окт. 2026
Источник: redhat
CVSS3: 5.4

Описание

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

A flaw was found in httpd. An integer overflow in the mod_dav_fs module occurs when processing Web Distributed Authoring and Versioning (WebDAV) PROPPATCH requests that declare an excessive number of XML namespaces. An authenticated remote attacker with write access can exploit this flaw to crash server worker processes, causing a Denial of Service (DoS), and persistently corrupt the directory's property database.

Меры по смягчению последствий

If WebDAV capabilities are not required, disable the mod_dav_fs module:

  1. Comment out the dav_fs_module directive in /etc/httpd/conf.modules.d/00-dav.conf:
#LoadModule dav_fs_module modules/mod_dav_fs.so

Alternatively, if WebDAV is required but property modifications can be restricted, block the PROPPATCH method in the affected <Directory> or <Location> configuration block:

<Location "/webdav"> <Limit PROPPATCH> Require all denied </Limit> </Location>
  1. Apply the configuration changes:
systemctl reload httpd

Caveats: Disabling mod_dav_fs disables file-backed WebDAV shares across the server. Blocking PROPPATCH prevents clients from manipulating WebDAV dead properties. Warning: Reloading or restarting the httpd service will temporarily impact active client connections.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10httpdAffected
Red Hat Enterprise Linux 6httpdOut of support scope
Red Hat Enterprise Linux 7httpdAffected
Red Hat Enterprise Linux 8httpd:2.4/httpdAffected
Red Hat Enterprise Linux 9httpdAffected
Red Hat Hardened Imageshttpd-main-2.4.69-1.hum1FixedRHSA-2026:7485802.10.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2544798httpd: httpd: Denial of Service via integer overflow in mod_dav_fs

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
3 дня назад

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

CVSS3: 8.8
debian
3 дня назад

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 al ...

CVSS3: 8.8
github
3 дня назад

Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory's property database via PROPPATCH requests declaring many XML namespaces.

5.4 Medium

CVSS3

Уязвимость CVE-2026-93546