CVE-2024-36387
Published: 1 July 2024
Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
Notes
Author | Note |
---|---|
mdeslaur | While this issue was introduced in 2.4.55, the http2 module was backported to earlier Ubuntu releases. |
Priority
Status
Package | Release | Status |
---|---|---|
apache2 Launchpad, Ubuntu, Debian |
bionic |
Needs triage
|
focal |
Needed
|
|
jammy |
Needed
|
|
mantic |
Needed
|
|
noble |
Needed
|
|
trusty |
Needs triage
|
|
upstream |
Released
(2.4.60-1)
|
|
xenial |
Needs triage
|
|
Patches: upstream: https://github.com/apache/httpd/commit/c69a51bff8157e403121f8436d85dde21ad28bd2 upstream: https://svn.apache.org/viewvc?view=revision&revision=1918557 upstream: https://github.com/apache/httpd/commit/62aa64e5aea21dd969db97aded4443c98c0735ac |