CVE-2025-55753

Updated: 2025-12-22 02:47:23.513767

Description:

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66. Users are recommended to upgrade to version 2.4.66, which fixes the issue.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU mod_md 2.4.19 7.5 HIGH Released CLSA-2025:1767026442 2025-12-29 17:05:15
AlmaLinux 9.2 ESU httpd 2.4.53 7.5 HIGH In Testing 2025-12-24 12:48:34
CentOS 8.4 ELS httpd 2.4.37 7.5 HIGH Not Vulnerable 2026-01-05 20:08:18
CentOS 8.5 ELS httpd 2.4.37 7.5 HIGH Not Vulnerable 2026-01-05 20:08:20
CentOS Stream 8 ELS httpd 2.4.37 7.5 HIGH In Testing 2025-12-25 14:34:49
TuxCare 9.6 ESU httpd 2.4.62 7.5 HIGH Not Vulnerable 2025-12-29 17:05:21
TuxCare 9.6 ESU mod_md 2.4.26 7.5 HIGH Released CLSA-2026:1767629031 2026-01-05 20:08:09