CVE-2024-27316: Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Accounts. The issue was addressed with improved checks.
Other sources
AirDrop. This issue was addressed through improved state management.
— Apple
Apache HTTP Server is vulnerable to a denial of service, caused by the failure to check or limit the use of HTTP/2 CONTINUATION frames that can be sent within a single stream. By sending a stream of CONTINUATION frames that will not be appended to the header list in memory but will still be processed and decoded by the server or will be appended to the header list, a remote attacker could exploit this vulnerability to cause an out of memory (OOM) crash.
— IBM
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
— Microsoft
apache. This is a vulnerability in open source code and Apple Software is among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
— Launchpad
Credit
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-40804
- CVE-2023-38709
- CVE-2024-24795
- CVE-2024-27316
- CVE-2024-40783
- CVE-2024-40774
- CVE-2024-40814
- CVE-2024-40775
- CVE-2024-27877
- CVE-2024-27878
- CVE-2024-40799
- CVE-2024-27873
- CVE-2024-2004
- CVE-2024-2379
- CVE-2024-2398
- CVE-2024-2466
- CVE-2024-40827
- CVE-2024-40815
- CVE-2024-40795
- CVE-2023-6277
- CVE-2023-52356
- CVE-2024-40806
- CVE-2024-40777
- CVE-2024-40784
- CVE-2024-27863
- CVE-2024-40816
- CVE-2024-40788
- CVE-2024-40803
- CVE-2024-40805
- CVE-2024-40832
- CVE-2024-40796
- CVE-2024-6387
- CVE-2024-40781
- CVE-2024-40802
- CVE-2024-40823
- CVE-2024-27882
- CVE-2024-27883
- CVE-2024-40778
- CVE-2024-40800
- CVE-2023-27952
- CVE-2024-40817
- CVE-2024-40824
- CVE-2024-27871
- CVE-2024-27881
- CVE-2024-40821
- CVE-2024-40798
- CVE-2024-27872
- CVE-2024-27862
- CVE-2024-40833
- CVE-2024-40835
- CVE-2024-40836
- CVE-2024-40807
- CVE-2024-40834
- CVE-2024-40809
- CVE-2024-40812
- CVE-2024-40787
- CVE-2024-40793
- CVE-2024-40818
- CVE-2024-40822
- CVE-2024-40828
- CVE-2024-40811
- CVE-2024-40776
- CVE-2024-40782
- CVE-2024-40779
- CVE-2024-40780
- CVE-2024-40785
- CVE-2024-40789
- CVE-2024-4558
- CVE-2024-40794
- CVE-2024-54564
- CVE-2024-44306
- CVE-2024-44307
- CVE-2024-44141
- CVE-2024-44199
- CVE-2024-40810
- CVE-2024-44305
- CVE-2024-44205
- CVE-2024-54551
- CVE-2024-44185
- CVE-2024-44206
Frequently Asked Questions
What is the severity of CVE-2024-27316?
The severity of CVE-2024-27316 has not been explicitly classified, but it affects multiple platforms including Apache HTTP Server and macOS.
How do I fix CVE-2024-27316?
To fix CVE-2024-27316, upgrade Apache HTTP Server to version 2.4.62 or later, or update macOS to version 14.6 or later.
Which software versions are affected by CVE-2024-27316?
CVE-2024-27316 affects Apache HTTP Server versions from 2.4.17 to before 2.4.59, and macOS versions up to 14.6.
Is CVE-2024-27316 specific to any operating systems?
Yes, CVE-2024-27316 affects multiple operating systems including Red Hat, Fedora, and Apple's macOS.
What should I do if I cannot upgrade to the fixed version for CVE-2024-27316?
If an upgrade is not possible, consider implementing temporary mitigation strategies such as adjusting server configurations to limit header sizes.