Fedora Account System
Red Hat Associate
Red Hat Customer
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
This issue has been addressed in the following products: Red Hat JBoss Core Services 2.4.62.SP4 Via RHSA-2026:27201 https://access.redhat.com/errata/RHSA-2026:27201
This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2026:27200 https://access.redhat.com/errata/RHSA-2026:27200