Impact
The Apache HTTP Server mod_http2 module contains a use‑after‑free vulnerability that can lead to arbitrary memory manipulation. The flaw arises when concurrent access to the shared session->bbtmp data structure triggers a re‑entrancy bug, allowing an attacker to corrupt server memory or cause a crash. This type of vulnerability can compromise the integrity of running processes and potentially expose sensitive data if memory corruption results in information leakage.
Affected Systems
It affects Apache HTTP Server versions 2.4.0 through 2.4.68 whenever the mod_http2 module is built and loaded. The vulnerability is present in official releases from the Apache Software Foundation and any custom builds that enable HTTP/2 support.
Risk and Exploitability
The CVSS v3.1 base score is 9.8, indicating a critical severity. EPSS is not available and the flaw is not listed in the CISA KEV catalog. The description does not explicitly state an exploitation method; however, the flaw is reachable via HTTP/2 traffic and the likely attack vector is inferred to be network‑based. An attacker could submit crafted HTTP/2 requests to trigger the re‑entrancy and provoke memory corruption, which may lead to denial of service or more serious compromise depending on the environment and privileges of the running process.
OpenCVE Enrichment