Resource management error in Apache HTTP Server - CVE-2023-43622

 

Resource management error in Apache HTTP Server - CVE-2023-43622

Published: October 19, 2023 / Updated: January 4, 2026


Vulnerability identifier: #VU82247
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43622
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the server when processing HTTP/2 connections with window size of 0. A remote attacker can exhaust available workers on the server and perform a denial of service (DoS) attack.


Affected software

Apache HTTP Server
Gentoo Linux
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Slackware Linux
Ubuntu
Anolis OS
SecurityCenter
IBM Rational Build Forge
EasyApache
HP-UX
mod_http2 (Red Hat package)
apache2 (Ubuntu package)
httpd
mod_ssl
mod_session
mod_proxy_html
mod_lua
mod_ldap
httpd-tools
httpd-devel
httpd-core
httpd-doc
httpd-filesystem
httpd-manual
httpd24
apache2 (Debian package)
www-servers/apache
Citrix License Server

How to mitigate CVE-2023-43622

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.58
SecurityCenter - addressed in versions SC-202312.1, 6.2.1
IBM Rational Build Forge - update to 8.0.0.26
mod_http2 (Red Hat package) - update to 2.0.26-1.el9
apache2 (Ubuntu package) - addressed in versions 2.4.41-4ubuntu3.15, 2.4.52-1ubuntu4.7, 2.4.55-1ubuntu2.1, 2.4.57-2ubuntu2.1
httpd - update to 2.4.58
mod_ssl - update to 2.4.58-1
mod_session - update to 2.4.58-1
mod_proxy_html - update to 2.4.58-1
mod_lua - update to 2.4.58-1
mod_ldap - update to 2.4.58-1
httpd-tools - update to 2.4.58-1
httpd-devel - update to 2.4.58-1
httpd-core - update to 2.4.58-1
httpd - update to 2.4.58-1
httpd - update to 2.4.58-1
httpd-doc - update to 2.4.58-1
httpd-filesystem - update to 2.4.58-1
httpd-manual - update to 2.4.58-1
httpd24 - update to 2.4.58-1.101
apache2 (Debian package) - addressed in versions 2.4.59-1~deb11u1, 2.4.59-1~deb12u1
www-servers/apache - update to 2.4.68
EasyApache - update to 4 2023-10-25
Citrix License Server - update to 11.17.2.0 45000

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins