Back

HIGH

httpd: Incomplete handling of LimitRequestFields directive in mod_http2

Published Dec 5, 2016

Description

The mod_http2 module in the Apache HTTP Server 2.4.17 through 2.4.23, when the Protocols configuration includes h2 or h2c, does not restrict request-header length, which allows remote attackers to cause a denial of service (memory consumption) via crafted CONTINUATION frames in an HTTP/2 request.

Affected products

Remediation

Red Hat statement

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Red Hat mitigation

As a temporary workaround - HTTP/2 can be disabled by changing the configuration by removing h2 and h2c from the Protocols line(s) in the configuration file. The resulting line should read: Protocols http/1.1

Metrics

References (34)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Dec 5, 2016
Updated Aug 6, 2024
Reserved Oct 18, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 4, 2016