CVE-2024-27316

Public on 2024-04-04
Modified on 2024-04-05
Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Severity
Important severity
Important
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
HAQM Linux 1 httpd No Fix Planned
HAQM Linux 1 httpd24 2024-04-25 ALAS-2024-1931 Fixed
HAQM Linux 2 - Core mod_http2 2024-04-24 ALAS2-2024-2524 Fixed
HAQM Linux 2023 mod_http2 2024-04-25 ALAS2023-2024-595 Fixed

CVSS Scores

Score Type Score Vector
HAQM Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H