Wind River Support Network

HomeDefectsLIN1021-8087
Fixed

LIN1021-8087 : Security Advisory - apache2 - CVE-2024-27316

Created: Apr 3, 2024    Updated: Apr 29, 2024
Resolved Date: Apr 28, 2024
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion.

https://nvd.nist.gov/vuln/detail/CVE-2024-27316

CVEs


Live chat
Online