Synopsis
Moderate: mod_http2 security, bug fix, and enhancement update
Type/Severity
Security Advisory: Moderate
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for mod_http2 is now available for Red Hat Enterprise Linux 9.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.
Security Fix(es):
- httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. (CVE-2026-48913)
- httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
Bug Fix(es) and Enhancement(s):
- address CVE-2026-43951 and CVE-2026-48913 in mod_http2 [rhel-9] (JIRA:RHEL-190583)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 9 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 9 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x
-
Red Hat Enterprise Linux for Power, little endian 9 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le
-
Red Hat Enterprise Linux for ARM 64 9 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64
-
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x
Fixes
-
BZ - 2486405
- CVE-2026-48913 httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service.
-
BZ - 2486415
- CVE-2026-43951 httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 9
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| x86_64 |
|
mod_http2-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: 624ddb8883a44786afe061d2c45170db0e78479523c3c8071943fb99709dcfd4 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: aac63844996f65c80d90a35e584133f36cb6a6be3d4e1af93f1862baf7af0ec8 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: ae3becc958f2eebd7d503c4d2c0e5ca78094af2f73236f07a151f639ab82fb77 |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| x86_64 |
|
mod_http2-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: 624ddb8883a44786afe061d2c45170db0e78479523c3c8071943fb99709dcfd4 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: aac63844996f65c80d90a35e584133f36cb6a6be3d4e1af93f1862baf7af0ec8 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: ae3becc958f2eebd7d503c4d2c0e5ca78094af2f73236f07a151f639ab82fb77 |
Red Hat Enterprise Linux for IBM z Systems 9
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| s390x |
|
mod_http2-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: c5b8c9f589c9e260230f5e01ef5cff4213eaf55297303696a81ad2c400bad3d7 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 8306acbdeea5ec129fc42606b243ddfc87a311cfb719f2cf06a292162044732a |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 3e6e3e0720392284cec01f263d2c69c347bbe76ca5ad53ca9d5ba66bd77c4590 |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| s390x |
|
mod_http2-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: c5b8c9f589c9e260230f5e01ef5cff4213eaf55297303696a81ad2c400bad3d7 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 8306acbdeea5ec129fc42606b243ddfc87a311cfb719f2cf06a292162044732a |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 3e6e3e0720392284cec01f263d2c69c347bbe76ca5ad53ca9d5ba66bd77c4590 |
Red Hat Enterprise Linux for Power, little endian 9
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| ppc64le |
|
mod_http2-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 01e36ddd94e3cfd338e0d84a73d2a52d63dcc4503308d8c4c5db94e72a0016fb |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: a58096d469963542e519365539830a84490ec8d663e4ec2fc921052a01081bb5 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 7e0d86f18e643c071af85d12e0c9d5b5334902900f80293389bf206206169934 |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| ppc64le |
|
mod_http2-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 01e36ddd94e3cfd338e0d84a73d2a52d63dcc4503308d8c4c5db94e72a0016fb |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: a58096d469963542e519365539830a84490ec8d663e4ec2fc921052a01081bb5 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 7e0d86f18e643c071af85d12e0c9d5b5334902900f80293389bf206206169934 |
Red Hat Enterprise Linux for ARM 64 9
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| aarch64 |
|
mod_http2-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 18213307cd7f451d644a7da4401fbd6b9d091a5920cae61ffb670d402401aa55 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: da4183ac8e30b9be5b581a597ed5a2aca114ec626a07b94ccc40016ebd86aaec |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 281eee5dd12caffe99dcbf0715a67fd12e69ede86819041060aed5caa5e74d95 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| aarch64 |
|
mod_http2-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 18213307cd7f451d644a7da4401fbd6b9d091a5920cae61ffb670d402401aa55 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: da4183ac8e30b9be5b581a597ed5a2aca114ec626a07b94ccc40016ebd86aaec |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 281eee5dd12caffe99dcbf0715a67fd12e69ede86819041060aed5caa5e74d95 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| ppc64le |
|
mod_http2-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 01e36ddd94e3cfd338e0d84a73d2a52d63dcc4503308d8c4c5db94e72a0016fb |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: a58096d469963542e519365539830a84490ec8d663e4ec2fc921052a01081bb5 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 7e0d86f18e643c071af85d12e0c9d5b5334902900f80293389bf206206169934 |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| x86_64 |
|
mod_http2-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: 624ddb8883a44786afe061d2c45170db0e78479523c3c8071943fb99709dcfd4 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: aac63844996f65c80d90a35e584133f36cb6a6be3d4e1af93f1862baf7af0ec8 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: ae3becc958f2eebd7d503c4d2c0e5ca78094af2f73236f07a151f639ab82fb77 |
Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| aarch64 |
|
mod_http2-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 18213307cd7f451d644a7da4401fbd6b9d091a5920cae61ffb670d402401aa55 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: da4183ac8e30b9be5b581a597ed5a2aca114ec626a07b94ccc40016ebd86aaec |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 281eee5dd12caffe99dcbf0715a67fd12e69ede86819041060aed5caa5e74d95 |
Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| s390x |
|
mod_http2-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: c5b8c9f589c9e260230f5e01ef5cff4213eaf55297303696a81ad2c400bad3d7 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 8306acbdeea5ec129fc42606b243ddfc87a311cfb719f2cf06a292162044732a |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 3e6e3e0720392284cec01f263d2c69c347bbe76ca5ad53ca9d5ba66bd77c4590 |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| x86_64 |
|
mod_http2-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: 624ddb8883a44786afe061d2c45170db0e78479523c3c8071943fb99709dcfd4 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: aac63844996f65c80d90a35e584133f36cb6a6be3d4e1af93f1862baf7af0ec8 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.x86_64.rpm
|
SHA-256: ae3becc958f2eebd7d503c4d2c0e5ca78094af2f73236f07a151f639ab82fb77 |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| aarch64 |
|
mod_http2-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 18213307cd7f451d644a7da4401fbd6b9d091a5920cae61ffb670d402401aa55 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: da4183ac8e30b9be5b581a597ed5a2aca114ec626a07b94ccc40016ebd86aaec |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.aarch64.rpm
|
SHA-256: 281eee5dd12caffe99dcbf0715a67fd12e69ede86819041060aed5caa5e74d95 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| ppc64le |
|
mod_http2-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 01e36ddd94e3cfd338e0d84a73d2a52d63dcc4503308d8c4c5db94e72a0016fb |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: a58096d469963542e519365539830a84490ec8d663e4ec2fc921052a01081bb5 |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.ppc64le.rpm
|
SHA-256: 7e0d86f18e643c071af85d12e0c9d5b5334902900f80293389bf206206169934 |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8
| SRPM |
|
mod_http2-2.0.26-6.el9_8.2.src.rpm
|
SHA-256: 75d224f6ffcb0bc88108e4074722c57e0edec6482dc0481d43f0da806875a5db |
| s390x |
|
mod_http2-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: c5b8c9f589c9e260230f5e01ef5cff4213eaf55297303696a81ad2c400bad3d7 |
|
mod_http2-debuginfo-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 8306acbdeea5ec129fc42606b243ddfc87a311cfb719f2cf06a292162044732a |
|
mod_http2-debugsource-2.0.26-6.el9_8.2.s390x.rpm
|
SHA-256: 3e6e3e0720392284cec01f263d2c69c347bbe76ca5ad53ca9d5ba66bd77c4590 |