RHSA-2024:8680: Low: mod_http2 security update
Low: modhttp2 security update
Other sources
The modh2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.Security Fix(es): modhttp2: DoS by null pointer in websocket over HTTP/2 (CVE-2024-36387) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:8680?
The severity of RHSA-2024:8680 is classified as low.
What vulnerability does RHSA-2024:8680 address?
RHSA-2024:8680 addresses a denial of service vulnerability caused by a null pointer in websocket over HTTP/2, identified as CVE-2024-36387.
How do I fix RHSA-2024:8680?
To fix RHSA-2024:8680, it is recommended to apply the latest security updates for the affected versions of the mod_http2 module.
Which software is affected by RHSA-2024:8680?
RHSA-2024:8680 affects multiple Red Hat Enterprise Linux products specifically related to the mod_http2 Apache HTTPD module.
What is the impact of the vulnerability in RHSA-2024:8680?
The impact of the vulnerability in RHSA-2024:8680 can potentially lead to a denial of service condition, affecting the availability of HTTP/2 services.