Resource exhaustion in Apache HTTP Server - CVE-2024-27316
Published: April 4, 2024 / Updated: July 26, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling HTTP/2 requests. A remote attacker can send specially crafted HTTP/2 requests to the server and perform a denial of service (DoS) attack.
Affected software
Undertow
HP-UX Apache Web Server
Debian Linux
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
Oracle Linux
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
macOS
Slackware Linux
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
Server Applications Module
SUSE Package Hub 15
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Solaris
Data Lakehouse
Oracle Communications Cloud Native Core Network Data Analytics Function
IBM MQ Operator
Red Hat OpenShift Dev Spaces
EasyApache
Dell Secure Connect Gateway
IBM Rational Build Forge
IBM Power Hardware Management Console (HMC)
EMC NetWorker Server
FortiSandbox
Communications Unified Assurance
JBoss Enterprise Application Platform
JBoss Core Services
FortiSwitch
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
apache2 (Ubuntu package)
eap7-netty-xnio-transport (Red Hat package)
eap7-log4j-jboss-logmanager (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
eap7-ironjacamar (Red Hat package)
eap7-jboss-server-migration (Red Hat package)
mod_http2
mod_http2-help
mod_http2-debugsource
mod_http2-debuginfo
http2 (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
eap7-bouncycastle (Red Hat package)
mod_md
mod_http2 (Red Hat package)
eap7-undertow (Red Hat package)
eap7-jandex (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
mod_proxy_html
httpd-manual
httpd-filesystem
mod_ssl
mod_session
httpd
httpd-devel
httpd-tools
mod_ldap
httpd-help
httpd-debugsource
httpd-debuginfo
apache2-example-pages
apache2-tls13-devel
apache2-tls13-debugsource
apache2-devel
apache2-tls13-debuginfo
apache2-debugsource
apache2-debuginfo
apache2-utils
apache2-worker-debuginfo
apache2-worker
apache2-tls13-doc
apache2-doc
apache2-prefork
apache2-tls13-worker-debuginfo
apache2-tls13-utils-debuginfo
apache2-tls13-worker
apache2-tls13-utils
apache2-tls13-prefork
apache2-utils-debuginfo
apache2-prefork-debuginfo
apache2-tls13
apache2-tls13-prefork-debuginfo
apache2
apache2-tls13-example-pages
jbcs-httpd24-httpd (Red Hat package)
apache2-event-debuginfo
apache2-prefork-debugsource
apache2-manual
apache2-event-debugsource
apache2-worker-debugsource
apache2-utils-debugsource
apache2-event
apache2 (Debian package)
httpd24
www-servers/apache
jbcs-httpd24-mod_security (Red Hat package)
eap7-hal-console (Red Hat package)
eap7-jboss-xnio-base (Red Hat package)
eap7-netty-transport-native-epoll (Red Hat package)
eap7-netty (Red Hat package)
eap7-jboss-remoting (Red Hat package)
eap7-wildfly (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
IBM Cloud Pak for Multicloud Management
IBM Cloud Pak System
IBM Aspera Console
Maximo Application Suite - IoT Component
IBM supplied MQ Advanced container images
Total Storage Service Console (TSSC) / TS4500 IMC
NetWorker Management Console (NMC)
How to mitigate CVE-2024-27316
Data Lakehouse - update to 1.1.0.0
Undertow - addressed in versions 2.2.33, 2.3.14
FortiSandbox - update to 4.4.6
JBoss Enterprise Application Platform - update to 7.4.18
FortiSwitch - update to 7.4.4
macOS - update to 14.6 23G80
apache2 (Ubuntu package) - addressed in versions Ubuntu Pro, 2.4.41-4ubuntu3.17, 2.4.52-1ubuntu4.9, 2.4.57-2ubuntu2.4, 2.4.58-1ubuntu8.1
eap7-netty-xnio-transport (Red Hat package) - addressed in versions 0.1.10-1.Final_redhat_00001.1.el7eap, 0.1.10-1.Final_redhat_00001.1.el8eap, 0.1.10-1.Final_redhat_00001.1.el9eap
eap7-log4j-jboss-logmanager (Red Hat package) - addressed in versions 1.3.1-1.Final_redhat_00002.1.el7eap, 1.3.1-1.Final_redhat_00002.1.el8eap, 1.3.1-1.Final_redhat_00002.1.el9eap
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.20-4.el7jbcs, 1.3.20-4.el8jbcs
eap7-ironjacamar (Red Hat package) - addressed in versions 1.5.17-1.Final_redhat_00001.1.el7eap, 1.5.17-1.Final_redhat_00001.1.el8eap, 1.5.17-1.Final_redhat_00001.1.el9eap
eap7-jboss-server-migration (Red Hat package) - addressed in versions 1.10.0-37.Final_redhat_00037.1.el7eap, 1.10.0-37.Final_redhat_00037.1.el8eap, 1.10.0-37.Final_redhat_00037.1.el9eap
mod_http2 - update to 1.15.7-8
mod_http2-help - update to 1.15.13-2
mod_http2-debugsource - update to 1.15.13-2
mod_http2-debuginfo - update to 1.15.13-2
mod_http2 - update to 1.15.13-2
http2 (Red Hat package) - addressed in versions 1.15.19-3.el9_0.6, 1.15.19-4.el9_2.6, 1.15.19-5.el9_3.1
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-37.el7jbcs, 1.15.19-37.el8jbcs
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.43.0-13.el7jbcs, 1.43.0-13.el8jbcs
eap7-bouncycastle (Red Hat package) - addressed in versions 1.78.1-1.redhat_00002.1.el7eap, 1.78.1-1.redhat_00002.1.el8eap, 1.78.1-1.redhat_00002.1.el9eap
mod_md - update to 2.0.8-8
IBM MQ Operator - addressed in versions 2.0.22, 3.1.3
mod_http2 (Red Hat package) - update to 2.0.26-2.el9_4
mod_http2 - update to 2.0.27-1
mod_http2 - addressed in versions 2.0.27-1.fc38, 2.0.27-1.fc39, 2.0.27-1.fc40
eap7-undertow (Red Hat package) - addressed in versions 2.2.33-1.SP1_redhat_00001.1.el7eap, 2.2.33-1.SP1_redhat_00001.1.el8eap, 2.2.33-1.SP1_redhat_00001.1.el9eap
IBM Cloud Pak for Multicloud Management - update to 2.3 FP11
IBM Cloud Pak System - update to 2.3.4.1
eap7-jandex (Red Hat package) - addressed in versions 2.4.5-1.Final_redhat_00001.1.el7eap, 2.4.5-1.Final_redhat_00001.1.el8eap, 2.4.5-1.Final_redhat_00001.1.el9eap
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-6.el7jbcs, 2.4.24-6.el8jbcs
mod_proxy_html - update to 2.4.37-62.0.3
httpd-manual - update to 2.4.37-62.0.3
httpd-filesystem - update to 2.4.37-62.0.3
mod_ssl - update to 2.4.37-62.0.3
mod_session - update to 2.4.37-62.0.3
httpd - update to 2.4.37-62.0.3
httpd-devel - update to 2.4.37-62.0.3
httpd-tools - update to 2.4.37-62.0.3
mod_ldap - update to 2.4.37-62.0.3
httpd-help - update to 2.4.43-24
httpd-devel - update to 2.4.43-24
httpd-filesystem - update to 2.4.43-24
mod_ldap - update to 2.4.43-24
httpd-tools - update to 2.4.43-24
httpd-debugsource - update to 2.4.43-24
mod_proxy_html - update to 2.4.43-24
httpd-debuginfo - update to 2.4.43-24
mod_ssl - update to 2.4.43-24
mod_md - update to 2.4.43-24
mod_session - update to 2.4.43-24
httpd - update to 2.4.43-24
apache2-example-pages - addressed in versions 2.4.51-35.41.1, 2.4.66-150400.6.57.1
apache2-tls13-devel - update to 2.4.51-35.41.1
apache2-tls13-debugsource - update to 2.4.51-35.41.1
apache2-devel - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-tls13-debuginfo - update to 2.4.51-35.41.1
apache2-debugsource - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-debuginfo - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-utils - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-worker-debuginfo - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-worker - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-tls13-doc - update to 2.4.51-35.41.1
apache2-doc - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.66-150400.6.57.1
apache2-prefork - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-tls13-worker-debuginfo - update to 2.4.51-35.41.1
apache2-tls13-utils-debuginfo - update to 2.4.51-35.41.1
apache2-tls13-worker - update to 2.4.51-35.41.1
apache2-tls13-utils - update to 2.4.51-35.41.1
apache2-tls13-prefork - update to 2.4.51-35.41.1
apache2-utils-debuginfo - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-prefork-debuginfo - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-tls13 - update to 2.4.51-35.41.1
apache2-tls13-prefork-debuginfo - update to 2.4.51-35.41.1
apache2 - addressed in versions 2.4.51-35.41.1, 2.4.51-150200.3.62.1, 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-tls13-example-pages - update to 2.4.51-35.41.1
JBoss Core Services - update to 2.4.57 SP4
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-10.el7jbcs, 2.4.57-10.el8jbcs
apache2-event-debuginfo - addressed in versions 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
apache2-prefork-debugsource - update to 2.4.58-150600.5.3.1
apache2-manual - update to 2.4.58-150600.5.3.1
apache2-event-debugsource - update to 2.4.58-150600.5.3.1
apache2-worker-debugsource - update to 2.4.58-150600.5.3.1
apache2-utils-debugsource - update to 2.4.58-150600.5.3.1
apache2-event - addressed in versions 2.4.58-150600.5.3.1, 2.4.66-150400.6.57.1
httpd - update to 2.4.59
apache2 (Debian package) - addressed in versions 2.4.59-1~deb11u1, 2.4.59-1~deb12u1
httpd24 - update to 2.4.59-1.102
www-servers/apache - update to 2.4.62
HP-UX Apache Web Server - update to 2.4.62.00
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-36.el7jbcs, 2.9.3-36.el8jbcs
eap7-hal-console (Red Hat package) - addressed in versions 3.3.23-1.Final_redhat_00001.1.el7eap, 3.3.23-1.Final_redhat_00001.1.el8eap, 3.3.23-1.Final_redhat_00001.1.el9eap
IBM Aspera Console - update to 3.4.2 PL 10
eap7-jboss-xnio-base (Red Hat package) - addressed in versions 3.8.16-1.Final_redhat_00001.1.el7eap, 3.8.16-1.Final_redhat_00001.1.el8eap, 3.8.16-1.Final_redhat_00001.1.el9eap
Red Hat OpenShift Dev Spaces - update to 3.16.0
eap7-netty-transport-native-epoll (Red Hat package) - addressed in versions 4.1.108-1.Final_redhat_00001.1.el7eap, 4.1.108-1.Final_redhat_00001.1.el8eap, 4.1.108-1.Final_redhat_00001.1.el9eap
eap7-netty (Red Hat package) - addressed in versions 4.1.108-1.Final_redhat_00001.1.el7eap, 4.1.108-1.Final_redhat_00001.1.el8eap, 4.1.108-1.Final_redhat_00001.1.el9eap
EasyApache - update to 4 2024-4-8
eap7-jboss-remoting (Red Hat package) - addressed in versions 5.0.29-1.Final_redhat_00001.1.el7eap, 5.0.29-1.Final_redhat_00001.1.el8eap, 5.0.29-1.Final_redhat_00001.1.el9eap
Dell Secure Connect Gateway - update to 5.24.00.14
eap7-wildfly (Red Hat package) - addressed in versions 7.4.18-1.GA_redhat_00001.1.el7eap, 7.4.18-1.GA_redhat_00001.1.el8eap, 7.4.18-1.GA_redhat_00001.1.el9eap
IBM Rational Build Forge - update to 8.0.0.27
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.7.1-2.el7jbcs, 8.7.1-2.el8jbcs
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.17-r2, 9.3.5.1-r2
Total Storage Service Console (TSSC) / TS4500 IMC - update to 9.4.31
IBM Power Hardware Management Console (HMC) - addressed in versions 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1060.0
Oracle Solaris - update to 11.4 SRU 71
NetWorker Management Console (NMC) - update to 19.10.0.5
EMC NetWorker Server - update to 19.10.0.5
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- Slackware Linux update for httpd
- Fedora 38 update for mod_http2
- Fedora 39 update for mod_http2
- Fedora 40 update for mod_http2
- Multiple vulnerabilities in cPanel EasyApache
- Ubuntu update for apache2
- openEuler update for mod_http2
- Red Hat Enterprise Linux 8 update for the httpd:2.4 module
- Multiple vulnerabilities in Oracle Linux
- Ubuntu update for apache2
- Red Hat Enterprise Linux 9 update for mod_http2
- Ubuntu update for apache2
- Red Hat Enterprise Linux 9 update for mod_http2
- openEuler update for httpd
- SUSE update for apache2
- Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
- SUSE update for apache2
- Resource exhaustion in IBM Aspera Console
- SUSE update for apache2
- Red Hat Enterprise Linux 9.2 Extended Update Support update for mod_http2
- Red Hat Enterprise Linux 9.0 Extended Update Support update for mod_http2
- Red Hat Enterprise Linux 8.6 Extended Update Support update for the httpd:2.4 module
- Red Hat Enterprise Linux 8.8 Extended Update Support update for the httpd:2.4 module
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Undertow
- Debian update for apache2
- Oracle Solaris update for thrid-party components
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Data Analytics Function
- Multiple vulnerabilities in Communications Unified Assurance
- Resource exhaustion in IBM i
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in Apple macOS Sonoma
- Amazon Linux AMI update for httpd24
- Amazon Linux AMI update for mod_http2
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8
- Multiple vulnerabilities in Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 7
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces
- Gentoo update for Apache HTTPD
- Multiple vulnerabilities in IBM Rational Build Forge
- IBM Power Hardware Management Console (HMC) update for Apache HTTP Server
- Multiple vulnerabilities in Dell NetWorker And NetWorker Management Console
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple HTTP/2 CONTINUATION frames vulnerabilities in FortiSandbox
- Multiple HTTP/2 CONTINUATION frames vulnerabilities in FortiSwitch
- Total Storage Service Console (TSSC) / TS4500 IMC update for Apache HTTP Server
- Multiple vulnerabilities in HPE HP-UX Apache Web Server
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Anolis OS update for httpd:2.4 module
- Multiple vulnerabilities in IBM Cloud Pak for Multicloud Management
- SUSE update for apache2