CVE-2024-27316

Public on 2024-04-04
Modified on 2024-04-05
Description
HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.
Severity
Important severity
Important
CVSS v3 Base Score
7.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 1 httpd No Fix Planned
Amazon Linux 1 httpd24 2024-04-25 ALAS-2024-1931 Fixed
Amazon Linux 2 - Core mod_http2 2024-04-24 ALAS2-2024-2524 Fixed
Amazon Linux 2023 mod_http2 2024-04-25 ALAS2023-2024-595 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD CVSSv3 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H