CVE-2024-36387: Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2
Last updated 24 July 2024
Other sources
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.62-1~deb11u1Fixed in 2.4.61-1~deb11u1Fixed in 2.4.62-1~deb12u1Fixed in 2.4.62-1~deb12u2Fixed in 2.4.62-3
Event History
Frequently Asked Questions
What is the severity of CVE-2024-36387?
CVE-2024-36387 has a severity rating that indicates it can lead to server crashes and performance degradation.
How do I fix CVE-2024-36387?
To fix CVE-2024-36387, update your Apache2 package to versions 2.4.62-1~deb11u1, 2.4.61-1~deb11u1, 2.4.62-1~deb12u1, 2.4.62-1~deb12u2, or 2.4.62-3.
What causes the vulnerability CVE-2024-36387?
CVE-2024-36387 is caused by serving WebSocket protocol upgrades over HTTP/2 connections, which can lead to a Null Pointer dereference.
Who is affected by CVE-2024-36387?
CVE-2024-36387 affects users running specific versions of the Apache2 web server under Debian.
What are the potential impacts of CVE-2024-36387?
The potential impacts of CVE-2024-36387 include crashes of the server process and degraded performance.