Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
The product dereferences a pointer that it expects to be valid but is NULL.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http_server | Apache | 2.4.55 (including) | 2.4.59 (including) |
JBoss Core Services for RHEL 8 | RedHat | jbcs-httpd24-mod_http2-0:2.0.29-3.el8jbcs | * |
JBoss Core Services on RHEL 7 | RedHat | jbcs-httpd24-mod_http2-0:2.0.29-3.el7jbcs | * |
Red Hat Enterprise Linux 9 | RedHat | mod_http2-0:2.0.26-2.el9_4.1 | * |
Red Hat JBoss Core Services 2.4.62 | RedHat | mod_http2 | * |
Apache2 | Ubuntu | devel | * |
Apache2 | Ubuntu | esm-infra/focal | * |
Apache2 | Ubuntu | focal | * |
Apache2 | Ubuntu | jammy | * |
Apache2 | Ubuntu | mantic | * |
Apache2 | Ubuntu | noble | * |
Apache2 | Ubuntu | oracular | * |
Apache2 | Ubuntu | upstream | * |