CVE-2024-36387

Updated: 2025-02-06 12:19:54.189792

Description:

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0
CVSS Version 3.x LOW 3.7

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU httpd 2.4.53 3.7 LOW In Progress 2025-02-19 06:48:24
CentOS 7 ELS httpd 2.4.6 3.7 LOW Not Vulnerable 2025-02-09 00:26:13 Not vulnerable
CloudLinux 7 ELS httpd 2.4.6 3.7 LOW Not Vulnerable 2025-02-07 22:52:45
Oracle Linux 7 ELS httpd 2.4.6 3.7 LOW Not Vulnerable 2025-02-08 22:48:55