发布于3月6日3月6日 Members Red Hat: CVE-2024-36387: mod_http2: DoS by null pointer in websocket over HTTP/2 (Multiple Advisories) Severity 3 CVSS (AV:N/AC:H/Au:N/C:N/I:N/A:P) Published 07/01/2024 Created 11/05/2024 Added 11/04/2024 Modified 11/04/2024 Description Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. Solution(s) redhat-upgrade-mod_http2 redhat-upgrade-mod_http2-debuginfo redhat-upgrade-mod_http2-debugsource References CVE-2024-36387 RHSA-2024:8680