mod_http2-2.0.26-6.el9_8
エラータID: AXSA:2026-1297:01
Release date:
Sunday, July 19, 2026 - 15:46
Subject:
mod_http2-2.0.26-6.el9_8
Affected Channels:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.
Security Fix(es):
* httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-53020
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Solution:
Update packages.
CVEs:
CVE-2025-53020
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Additional Info:
N/A
Download:
SRPMS
- mod_http2-2.0.26-6.el9_8.src.rpm
MD5: c727612689b8f7462b5934c97368bedf
SHA-256: 06cb770a9b07ca5247566059484e5c37e8c0bd70b67af56cc277fbc74298ae45
Size: 1.02 MB
Asianux Server 9 for x86_64
- mod_http2-2.0.26-6.el9_8.x86_64.rpm
MD5: 8de4bdf210c2d8d0680a6967275109b7
SHA-256: 7623920a8ddf100cf7213cfd1e27292b4c3f2f4c213dcdf66b73cb48b524d98f
Size: 162.67 kB