REDHAT-BUG-2419140: Integer Overflow
An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds.
This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66.
Users are recommended to upgrade to version 2.4.66, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.66
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2419140?
The severity of REDHAT-BUG-2419140 is high due to the potential for continuous certificate renewal attempts without delays.
How do I fix REDHAT-BUG-2419140?
To fix REDHAT-BUG-2419140, upgrade the Apache HTTP Server to a version later than 2.4.66.
What versions of Apache HTTP Server are affected by REDHAT-BUG-2419140?
Apache HTTP Server versions between 2.4.30 and 2.4.66 are affected by REDHAT-BUG-2419140.
What are the implications of REDHAT-BUG-2419140 for users?
Users may experience service disruptions due to repeated certificate renewal attempts when the backoff timer resets to zero.
Is there a workaround for REDHAT-BUG-2419140?
Currently, the recommended workaround for REDHAT-BUG-2419140 is to manually monitor certificate renewals to avoid hitting the failure limit.