HomeDefectsLIN1023-6899
Fixed

LIN1023-6899 : Security Advisory - apache2 - CVE-2024-36387

Created: Jul 1, 2024    Updated: Sep 15, 2024
Resolved Date: Aug 11, 2024
Found In Version: 10.23.30.1
Fix Version: 10.23.30.13
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Userspace

Description

Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.



CREATE(Triage):(User=admin) CVE-2024-36387 (https://nvd.nist.gov/vuln/detail/CVE-2024-36387)

CVEs