QID 356896

Date Published: 2024-01-16

QID 356896: Amazon Linux Security Advisory for httpd : ALAS2023-2023-433

Out-of-bounds read vulnerability in mod_macro of apache http server.
This issue affects apache http server: through 2.4.57. (
( CVE-2023-31122) a flaw was found in httpd.
This flaw allows an attacker opening an http/2 connection with an initial window size of 0 to block handling of that connection indefinitely in the apache http server.
This vulnerability can exhaust worker resources in the server, similar to the well-known "slow loris" attack pattern. (
( CVE-2023-43622) description a flaw was found in mod_http2.
When a http/2 stream is reset (rst frame) by a client, there is a time window were the request's memory resources were not reclaimed immediately.
Instead, de-allocation was deferred to connection close.
A client could send new requests and resets, keeping the connection busy and open, causing the memory footprint to keep on growing.
On connection close, all resources are reclaimed but the process might run out of memory before connection close. statement during "normal" http/2 use, the probability of encountering this issue is very low.
The kept memory would not become noticeable before the connection closes or times out. mitigation mitigation for this issue is either not available or the currently available options don't meet the red hat product security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. (
( CVE-2023-45802)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2023-2023-433 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 356896

    Software Advisories
    Advisory ID Software Component Link
    ALAS2023-2023-433 amazon linux 2023 URL Logo alas.aws.amazon.com/AL2023/ALAS-2023-433.html