CVE-2022-30556

Updated: 2025-08-20 03:13:23.101675

Description:

Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU httpd 2.4.53 7.5 HIGH Already Fixed 2023-11-08 08:35:59
CentOS 6 ELS httpd 2.2.15 7.5 HIGH Not Vulnerable 2022-06-21 08:47:34
CentOS 7 ELS httpd 2.4.6 7.5 HIGH Not Vulnerable 2023-09-19 09:30:21
CentOS 8.4 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2022:1656429967 2022-06-28 11:50:01
CentOS 8.5 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2022:1656430448 2022-06-28 11:50:01
CloudLinux 6 ELS httpd 2.2.15 7.5 HIGH Not Vulnerable 2022-06-21 08:47:34
Oracle Linux 6 ELS httpd 2.2.15 7.5 HIGH Not Vulnerable 2022-06-21 08:47:34
Ubuntu 16.04 ELS apache2 2.4.18 7.5 HIGH Released CLSA-2022:1656430949 2022-06-28 11:50:01
Ubuntu 18.04 ELS apache2 2.4.29 7.5 HIGH Already Fixed 2023-06-02 09:10:39