RHSA-2024:3402: Moderate: mod_http2 security update
Moderate: modhttp2 security update
Other sources
The modh2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.<br>Security Fix(es):<br><li> httpd: CONTINUATION frames DoS (CVE-2024-27316,VU#421644.4)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:3402?
The severity of RHSA-2024:3402 is classified as moderate.
What vulnerabilities are addressed in RHSA-2024:3402?
RHSA-2024:3402 addresses a denial of service vulnerability related to CONTINUATION frames in the HTTP2 protocol.
How do I fix RHSA-2024:3402?
To fix RHSA-2024:3402, you need to apply the latest security update for the affected Red Hat Enterprise Linux products.
Which versions of the software are affected by RHSA-2024:3402?
RHSA-2024:3402 affects various versions of Red Hat Enterprise Linux, including those for Power, x86_64, ARM 64, and IBM z Systems.
What is the main purpose of the mod_http2 update in RHSA-2024:3402?
The main purpose of the mod_http2 update in RHSA-2024:3402 is to enhance the security of the Apache HTTP server by mitigating the identified denial of service vulnerability.