REDHAT-BUG-2486405: Use After Free
Published Jun 8, 2026
·Updated
Use After Free vulnerability in Apache HTTP Server module modhttp2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Affected Software
1 affected component
Apache HTTP Server>=2.4.55<=2.4.67
Event History
Jun 8, 2026
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2486405?
The severity of REDHAT-BUG-2486405 is classified as medium with a score of 4.
2
How do I fix REDHAT-BUG-2486405?
To mitigate REDHAT-BUG-2486405, upgrade Apache HTTP Server to a version higher than 2.4.67.
3
What specific component is affected by REDHAT-BUG-2486405?
REDHAT-BUG-2486405 affects the mod_http2 module of the Apache HTTP Server.
4
What type of vulnerability is found in REDHAT-BUG-2486405?
REDHAT-BUG-2486405 is classified as a Use After Free vulnerability.
5
Which versions of Apache HTTP Server are impacted by REDHAT-BUG-2486405?
Apache HTTP Server versions from 2.4.55 through 2.4.67 are impacted by REDHAT-BUG-2486405.