CVE-2023-45802
Description
When a HTTP/2 stream was reset (RST frame) by a client, there was a time window were the requests memory resources were not reclaimed immediately. Instead, de-allocation was deferred to connection close. A client could send new requests and resets, keeping the connection busy and open and causing the memory footprint to keep on growing. On connection close, all resources were reclaimed, but the process might run out of memory before that.This was found by the reporter during testing ofCVE-2023-44487 (HTTP/2 Rapid Reset Exploit) with their own test client. During normal HTTP/2 use, the probability to hit this bug is very low. The kept memory would not become noticeable before the connection closes or times out.Users are recommended to upgrade to version 2.4.58, which fixes the issue.
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2023-45802 are fixed in Apache 2.4.58 | Windows |
| Apache HTTP server (USN-6506-1) apache2_2.4.52-1ubuntu4.7_i386.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.52-1ubuntu4.7_amd64.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.55-1ubuntu2.1_i386.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.55-1ubuntu2.1_amd64.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.57-2ubuntu2.1_i386.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.57-2ubuntu2.1_amd64.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.41-4ubuntu3.15_i386.deb | Linux |
| Apache HTTP server (USN-6506-1) apache2_2.4.41-4ubuntu3.15_amd64.deb | Linux |
| apache2 security update(DSA-5662-1) apache2_2.4.59-1~deb11u1_i386.deb | Linux |
| apache2 security update(DSA-5662-1) apache2_2.4.59-1~deb11u1_amd64.deb | Linux |
| apache2 security update(DSA-5662-1) apache2_2.4.59-1~deb12u1_i386.deb | Linux |
| apache2 security update(DSA-5662-1) apache2_2.4.59-1~deb12u1_amd64.deb | Linux |
| (RHSA-2024:2368)Moderate: security update mod_http2-2.0.26-1.el9.x86_64.rpm | Linux |
| (RHSA-2024:2368)Moderate: security update mod_http2-debuginfo-2.0.26-1.el9.x86_64.rpm | Linux |
| (RHSA-2024:2368)Moderate: security update mod_http2-debugsource-2.0.26-1.el9.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-debuginfo-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-debugsource-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-devel-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-filesystem-2.4.37-64.module+el8.10.0+21332+dfb1b40e.noarch.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-manual-2.4.37-64.module+el8.10.0+21332+dfb1b40e.noarch.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-tools-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update httpd-tools-debuginfo-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_http2-1.15.7-10.module+el8.10.0+21653+eaff63f0.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_http2-debuginfo-1.15.7-10.module+el8.10.0+21653+eaff63f0.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_http2-debugsource-1.15.7-10.module+el8.10.0+21653+eaff63f0.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_ldap-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_ldap-debuginfo-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_md-2.0.8-8.module+el8.9.0+19080+567b90f8.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_md-debuginfo-2.0.8-8.module+el8.9.0+19080+567b90f8.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_md-debugsource-2.0.8-8.module+el8.9.0+19080+567b90f8.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_proxy_html-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_proxy_html-debuginfo-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_session-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_session-debuginfo-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_ssl-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| (RHSA-2024:3121)Moderate: security update mod_ssl-debuginfo-2.4.37-64.module+el8.10.0+21332+dfb1b40e.x86_64.rpm | Linux |
| Httpd update (ELSA-2024-3121) httpd-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| Httpd-devel update (ELSA-2024-3121) httpd-devel-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| Httpd-filesystem update (ELSA-2024-3121) httpd-filesystem-2.4.37-64.module+el8.10.0+90271+3bc76a16.noarch.rpm | Linux |
| Httpd-manual update (ELSA-2024-3121) httpd-manual-2.4.37-64.module+el8.10.0+90271+3bc76a16.noarch.rpm | Linux |
| Httpd-tools update (ELSA-2024-3121) httpd-tools-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| Mod_http2 update (ELSA-2024-3121) mod_http2-1.15.7-10.module+el8.10.0+90327+96b8ea28.x86_64.rpm | Linux |
| Mod_ldap update (ELSA-2024-3121) mod_ldap-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| Mod_md update (ELSA-2024-3121) mod_md-2.0.8-8.module+el8.9.0+90011+2f9c6a23.x86_64.rpm | Linux |
| Mod_proxy_html update (ELSA-2024-3121) mod_proxy_html-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| Mod_session update (ELSA-2024-3121) mod_session-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| Mod_ssl update (ELSA-2024-3121) mod_ssl-2.4.37-64.module+el8.10.0+90271+3bc76a16.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) httpd-tools-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) httpd-manual-2.4.37-64.module+el8.10.0+1717+030a9fed.noarch.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) httpd-filesystem-2.4.37-64.module+el8.10.0+1717+030a9fed.noarch.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) httpd-devel-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) httpd-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) mod_ssl-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) mod_session-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) mod_proxy_html-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) mod_md-2.0.8-8.module+el8.9.0+1370+89cc8ad5.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) mod_ldap-2.4.37-64.module+el8.10.0+1717+030a9fed.x86_64.rpm | Linux |
| httpd:2.4 security update (RLSA-2024:3121) mod_http2-1.15.7-10.module+el8.10.0+1775+6b057638.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Server Applications Module 15-SP6) apache2-doc-2.4.51-150400.6.40.1.noarch.rpm | Linux |
| SUSE-SU-2024:3961-1(Server Applications Module 15-SP5) apache2-doc-2.4.51-150400.6.40.1.noarch.rpm | Linux |
| SUSE-SU-2024:3961-1(Server Applications Module 15-SP5) apache2-devel-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-debugsource-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-debuginfo-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-prefork-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-prefork-debuginfo-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-utils-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Server Applications Module 15-SP5) apache2-worker-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Server Applications Module 15-SP5) apache2-worker-debuginfo-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3961-1(Basesystem Module 15-SP5) apache2-utils-debuginfo-2.4.51-150400.6.40.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-debuginfo-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-debugsource-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Server Applications Module 15-SP5) apache2-devel-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Server Applications Module 15-SP5) apache2-doc-2.4.51-150400.6.43.1.noarch.rpm | Linux |
| SUSE-SU-2024:3999-1(Server Applications Module 15-SP6) apache2-doc-2.4.51-150400.6.43.1.noarch.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-prefork-debuginfo-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-utils-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-utils-debuginfo-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Server Applications Module 15-SP5) apache2-worker-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Server Applications Module 15-SP5) apache2-worker-debuginfo-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| SUSE-SU-2024:3999-1(Basesystem Module 15-SP5) apache2-prefork-2.4.51-150400.6.43.1.x86_64.rpm | Linux |
| Improper Resource Shutdown or Release Vulnerability (CVE-2023-45802) | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234