Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP4 security update
🔗 CVE IDs covered (10)
📋 Description
CVE-2025-53020 — mod_http2: Apache HTTP Server: HTTP/2 DoS by Memory Increase CVE-2026-27135 — nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination CVE-2026-28780 — Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow CVE-2026-29168 — httpd: mod_md: unrestricted OCSP response leads to resource exhaustion CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-33007 — httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash CVE-2026-33857 — httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions CVE-2026-34032 — httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check CVE-2026-34059 — httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() CVE-2026-49975 — httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack
🎯 Affected products67
- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-debuginfo-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-debuginfo-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-devel-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-devel-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-manual-0:2.4.62-13.el7jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-manual-0:2.4.62-13.el8jbcs.noarch as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-selinux-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-selinux-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-tools-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-httpd-tools-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-httpd-tools-debuginfo-0:2.4.62-13.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_http2-0:2.0.29-10.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_http2-0:2.0.29-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_http2-0:2.0.29-10.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_http2-0:2.0.29-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_http2-debuginfo-0:2.0.29-10.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_http2-debuginfo-0:2.0.29-10.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_jk-0:1.2.50-14.redhat_1.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_jk-0:1.2.50-14.redhat_1.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_jk-ap24-0:1.2.50-14.redhat_1.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_jk-ap24-0:1.2.50-14.redhat_1.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_jk-ap24-debuginfo-0:1.2.50-14.redhat_1.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-mod_jk-debuginfo-0:1.2.50-14.redhat_1.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-mod_ldap-0:2.4.62-13.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- +37 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: The attack surface can be reduced by disabling HTTP/2 support in Apache. Follow the guidance in Red Hat KCS article to: - Remove h2 and h2c from the Protocols directive - Disable mod_http2 and mod_proxy_http2 modules (if not required) https://access.redhat.com/node/7056356 Workaround: Disabling mod_md and restarting httpd will mitigate this flaw. Workaround: Disabling mod_dav_lock and restarting httpd will mitigate this flaw. Workaround: Disabling mod_authn_socache and restarting httpd will mitigate this flaw. Workaround: Disabling mod_proxy_ajp and restarting httpd will mitigate this flaw. Workaround: See the security bulletin for a detailed mitigation procedure.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:27200
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_core_services/2.4.62/html/red_hat_jboss_core_services_apache_http_server_2.4.62_service_pack_4_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379343
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2448754
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464940
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464952
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2464953
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2465296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2465299
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466753
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2466913
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2485371
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_27200.json