Resource management error in Apache HTTP Server - CVE-2023-43622
Published: October 19, 2023 / Updated: January 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the server when processing HTTP/2 connections with window size of 0. A remote attacker can exhaust available workers on the server and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Ubuntu
Anolis OS
SecurityCenter
IBM Rational Build Forge
EasyApache
HP-UX
mod_http2 (Red Hat package)
apache2 (Ubuntu package)
httpd
mod_ssl
mod_session
mod_proxy_html
mod_lua
mod_ldap
httpd-tools
httpd-devel
httpd-core
httpd-doc
httpd-filesystem
httpd-manual
httpd24
apache2 (Debian package)
www-servers/apache
Citrix License Server
How to mitigate CVE-2023-43622
SecurityCenter - addressed in versions SC-202312.1, 6.2.1
IBM Rational Build Forge - update to 8.0.0.26
mod_http2 (Red Hat package) - update to 2.0.26-1.el9
apache2 (Ubuntu package) - addressed in versions 2.4.41-4ubuntu3.15, 2.4.52-1ubuntu4.7, 2.4.55-1ubuntu2.1, 2.4.57-2ubuntu2.1
httpd - update to 2.4.58
mod_ssl - update to 2.4.58-1
mod_session - update to 2.4.58-1
mod_proxy_html - update to 2.4.58-1
mod_lua - update to 2.4.58-1
mod_ldap - update to 2.4.58-1
httpd-tools - update to 2.4.58-1
httpd-devel - update to 2.4.58-1
httpd-core - update to 2.4.58-1
httpd - update to 2.4.58-1
httpd - update to 2.4.58-1
httpd-doc - update to 2.4.58-1
httpd-filesystem - update to 2.4.58-1
httpd-manual - update to 2.4.58-1
httpd24 - update to 2.4.58-1.101
apache2 (Debian package) - addressed in versions 2.4.59-1~deb11u1, 2.4.59-1~deb12u1
www-servers/apache - update to 2.4.68
EasyApache - update to 4 2023-10-25
Citrix License Server - update to 11.17.2.0 45000
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Multiple vulnerabilities in cPanel EasyApache
- Amazon Linux AMI update for httpd24
- Multiple vulnerabilities in Tenable Security Center
- Ubuntu update for apache2
- Citrix License Server update for Apache HTTP Server
- HP-UX update for Apache Web Server
- Multiple vulnerabilities in IBM Rational Build Forge
- Red Hat Enterprise Linux 9 update for mod_http2
- Debian update for apache2
- Amazon Linux AMI update for httpd
- Anolis OS update for httpd
- Gentoo update for Apache HTTPD