Bugzilla – Bug 980370
VUL-0: CVE-2016-1546: apache2: mod_http2 denial-of-service by thread starvation
Last modified: 2016-05-20 09:37:18 UTC
rh#1336350 A vulnerability was found in httpd. By manipulating the flow control windows on streams, a client was able to block server threads for long times, causing starvation of worker threads. Connections could still be opened, but no streams where processed for these. This issue affected HTTP/2 support in 2.4.17 and 2.4.18. External references: http://httpd.apache.org/security/vulnerabilities_24.html Upstream commit: http://svn.apache.org/viewvc?view=revision&revision=1733727 Backported to 2.4.x branch via: http://svn.apache.org/viewvc?view=revision&revision=1734413 Included in 2.4.19, which was not released. References: https://bugzilla.redhat.com/show_bug.cgi?id=1336350 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-1546
bugbot adjusting priority
In Tubleweed it is fixed with 2.4.20 already.
Package submitted into 12sp2.
done