RHSA-2024:2564: Moderate: mod_http2 security update
Moderate: modhttp2 security update
Other sources
The modh2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.<br>Security Fix(es):<br><li> modhttp2: httpd: CONTINUATION frames DoS (CVE-2024-27316)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2564?
The severity of RHSA-2024:2564 is classified as moderate.
What is the main issue addressed in RHSA-2024:2564?
RHSA-2024:2564 addresses a denial of service vulnerability in the mod_http2 module of Apache httpd (CVE-2024-27316).
Which products are affected by RHSA-2024:2564?
RHSA-2024:2564 affects various Red Hat Enterprise Linux products including Server for Power, x86_64, and IBM z Systems.
How do I fix RHSA-2024:2564?
To fix RHSA-2024:2564, you should update your affected Red Hat Enterprise Linux installations to the latest version.
Is there a specific method to mitigate the denial of service problem in RHSA-2024:2564?
For mitigation of the denial of service issue in RHSA-2024:2564, applying the recommended updates should resolve the vulnerability.