Bug 2486405 (CVE-2026-48913) - CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
Summary: CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free...
Keywords:
Status: NEW
Alias: CVE-2026-48913
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2495884 2495885 2495887 2495888
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-08 16:02 UTC by OSIDB Bzimport
Modified: 2026-08-25 14:27 UTC (History)
9 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:34355 0 None None None 2026-07-01 16:38:52 UTC
Red Hat Product Errata RHSA-2026:50538 0 None None None 2026-08-05 00:53:00 UTC
Red Hat Product Errata RHSA-2026:50572 0 None None None 2026-08-05 02:59:19 UTC
Red Hat Product Errata RHSA-2026:55992 0 None None None 2026-08-18 14:46:37 UTC
Red Hat Product Errata RHSA-2026:56868 0 None None None 2026-08-19 13:32:29 UTC
Red Hat Product Errata RHSA-2026:56869 0 None None None 2026-08-19 13:28:54 UTC
Red Hat Product Errata RHSA-2026:59387 0 None None None 2026-08-25 14:27:12 UTC

Description OSIDB Bzimport 2026-06-08 16:02:24 UTC
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.

This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.

Comment 5 errata-xmlrpc 2026-07-01 16:38:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:34355 https://access.redhat.com/errata/RHSA-2026:34355

Comment 6 errata-xmlrpc 2026-08-05 00:52:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:50538 https://access.redhat.com/errata/RHSA-2026:50538

Comment 7 errata-xmlrpc 2026-08-05 02:59:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:50572 https://access.redhat.com/errata/RHSA-2026:50572

Comment 8 errata-xmlrpc 2026-08-18 14:46:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:55992 https://access.redhat.com/errata/RHSA-2026:55992

Comment 9 errata-xmlrpc 2026-08-19 13:28:52 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Core Services 2.4.62.SP5

Via RHSA-2026:56869 https://access.redhat.com/errata/RHSA-2026:56869

Comment 10 errata-xmlrpc 2026-08-19 13:32:27 UTC
This issue has been addressed in the following products:

  JBoss Core Services for RHEL 8

Via RHSA-2026:56868 https://access.redhat.com/errata/RHSA-2026:56868

Comment 11 errata-xmlrpc 2026-08-25 14:27:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:59387 https://access.redhat.com/errata/RHSA-2026:59387


Note You need to log in before you can comment on or make changes to this bug.