CVE-2024-27316
Vulnerability Summary
Timeline
Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
CVSS Metrics
- v3.1•HIGH•Score: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 91.33%• Percentile: 100%
Techniques & Countermeasures
- CWE-770•Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Affected Systems
- apache software foundation•apache http server
≥ 2.4.17, ≤ 2.4.58
- apache•http_server
≥ 2.4.17, < 2.4.59
- alpine•apache2
< 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0 | < 2.4.59-r0
- debian•apache2
< 2.4.59-1~deb11u1 | < 2.4.59-1~deb12u1 | < 2.4.59-1 | < 2.4.59-1
- fedoraproject•fedora
38 | 39 | 40
- netapp•ontap
9
- redhat•eap8-hibernate
< 0:6.2.26-1.Final_redhat_00001.1.el8eap | < 0:6.2.26-1.Final_redhat_00001.1.el9eap
- redhat•eap8-hibernate-core
< 0:6.2.26-1.Final_redhat_00001.1.el8eap | < 0:6.2.26-1.Final_redhat_00001.1.el9eap
- redhat•eap8-hibernate-envers
< 0:6.2.26-1.Final_redhat_00001.1.el8eap | < 0:6.2.26-1.Final_redhat_00001.1.el9eap
- redhat•eap8-jboss-remoting
< 0:5.0.29-1.Final_redhat_00001.1.el8eap | < 0:5.0.29-1.Final_redhat_00001.1.el9eap
- redhat•eap8-jboss-xnio-base
< 0:3.8.16-1.Final_redhat_00001.1.el8eap | < 0:3.8.16-1.Final_redhat_00001.1.el9eap
- redhat•eap8-jose4j
< 0:0.9.6-1.redhat_00001.1.el8eap | < 0:0.9.6-1.redhat_00001.1.el9eap
- redhat•eap8-undertow
< 0:2.3.14-1.SP1_redhat_00001.1.el8eap | < 0:2.3.14-1.SP1_redhat_00001.1.el9eap
- redhat•eap8-wildfly
< 0:8.0.2-5.GA_redhat_00012.1.el8eap | < 0:8.0.2-5.GA_redhat_00012.1.el9eap
- redhat•eap8-wildfly-java-jdk11
< 0:8.0.2-5.GA_redhat_00012.1.el8eap | < 0:8.0.2-5.GA_redhat_00012.1.el9eap
- redhat•eap8-wildfly-java-jdk17
< 0:8.0.2-5.GA_redhat_00012.1.el8eap | < 0:8.0.2-5.GA_redhat_00012.1.el9eap
- redhat•eap8-wildfly-modules
< 0:8.0.2-5.GA_redhat_00012.1.el8eap | < 0:8.0.2-5.GA_redhat_00012.1.el9eap
- redhat•httpd
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-debuginfo
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-debugsource
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-devel
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-filesystem
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-manual
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-tools
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•httpd-tools-debuginfo
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_http2
< 0:1.15.7-8.module+el8.9.0+21652+2dd1200b.5 | < 0:1.15.19-5.el9_3.1 | < 0:2.0.26-2.el9_4 | < 0:1.15.7-5.module+el8.6.0+21746+f601aac0.3 | < 0:1.15.19-4.el9_2.6 | < 0:1.15.19-3.el9_0.6
- redhat•mod_http2-debuginfo
< 0:1.15.7-8.module+el8.9.0+21652+2dd1200b.5 | < 0:1.15.19-5.el9_3.1 | < 0:2.0.26-2.el9_4 | < 0:1.15.7-5.module+el8.6.0+21746+f601aac0.3 | < 0:1.15.19-4.el9_2.6 | < 0:1.15.19-3.el9_0.6
- redhat•mod_http2-debugsource
< 0:1.15.7-8.module+el8.9.0+21652+2dd1200b.5 | < 0:1.15.19-5.el9_3.1 | < 0:2.0.26-2.el9_4 | < 0:1.15.7-5.module+el8.6.0+21746+f601aac0.3 | < 0:1.15.19-4.el9_2.6 | < 0:1.15.19-3.el9_0.6
- redhat•mod_ldap
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_ldap-debuginfo
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_md
< 1:2.0.8-8.module+el8.9.0+19080+567b90f8 | < 1:2.0.8-8.module+el8.3.0+6814+67d1e611
- redhat•mod_md-debuginfo
< 1:2.0.8-8.module+el8.9.0+19080+567b90f8 | < 1:2.0.8-8.module+el8.3.0+6814+67d1e611
- redhat•mod_md-debugsource
< 1:2.0.8-8.module+el8.9.0+19080+567b90f8 | < 1:2.0.8-8.module+el8.3.0+6814+67d1e611
- redhat•mod_proxy_html
< 1:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 1:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_proxy_html-debuginfo
< 1:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 1:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_session
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_session-debuginfo
< 0:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 0:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_ssl
< 1:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 1:2.4.37-47.module+el8.6.0+19809+6e655c60.7
- redhat•mod_ssl-debuginfo
< 1:2.4.37-62.module+el8.9.0+19699+7a7a2044 | < 1:2.4.37-47.module+el8.6.0+19809+6e655c60.7
References (34)
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://www.openwall.com/lists/oss-security/2024/04/03/16
- http://www.openwall.com/lists/oss-security/2024/04/04/4
- https://support.apple.com/kb/HT214119
- http://seclists.org/fulldisclosure/2024/Jul/18
- https://lists.debian.org/debian-lts-announce/2024/05/msg00013.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MIUBKSCJGPJ6M2U63V6BKFDF725ODLG7/
- https://security.netapp.com/advisory/ntap-20240415-0013/
- https://www.kb.cert.org/vuls/id/421644
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FO73U3SLBYFGIW2YKXOK7RI4D6DJSZ2B/
- https://access.redhat.com/errata/RHSA-2024:1786
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2268277
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1786.json
- https://access.redhat.com/security/cve/CVE-2024-27316
- https://www.cve.org/CVERecord?id=CVE-2024-27316
- https://nvd.nist.gov/vuln/detail/CVE-2024-27316
- https://nowotarski.info/http2-continuation-flood/
- https://access.redhat.com/errata/RHSA-2024:1872
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_1872.json
- https://access.redhat.com/errata/RHSA-2024:2564
- https://access.redhat.com/security/updates/classification/#moderate
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2564.json
- https://access.redhat.com/errata/RHSA-2024:2907
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_2907.json
- https://access.redhat.com/errata/RHSA-2024:3402
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3402.json
- https://access.redhat.com/errata/RHSA-2024:3417
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_3417.json
- https://access.redhat.com/errata/RHSA-2024:4390
- https://access.redhat.com/documentation/en-us/red_hat_jboss_enterprise_application_platform/8.0/
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhsa-2024_4390.json
- https://security-tracker.debian.org/tracker/CVE-2024-27316
- https://security.alpinelinux.org/vuln/CVE-2024-27316