HomeDefectsLIN1022-9597
Fixed

LIN1022-9597 : Security Advisory - apache2 - CVE-2024-36387

Created: Jul 1, 2024    Updated: Aug 6, 2024
Resolved Date: Aug 4, 2024
Found In Version: 10.22.33.1
Fix Version: 10.22.33.18
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.



CREATE(Triage):(User=admin) CVE-2024-36387 (https://nvd.nist.gov/vuln/detail/CVE-2024-36387)

CVEs