Linuxsecurity
Oracle Linux 10 mod_http2 DoS Vulnerabilities Disclosed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Oracle has released advisories for multiple denial-of-service (DoS) vulnerabilities affecting mod_http2 in Oracle Linux 10. The vulnerabilities include CVE-2026-43951, CVE-2026-48913, and CVE-2026-49975, all published on 2026-06-08. CVE-2026-49975 specifically allows for remote DoS attacks via compression bomb and Slowloris-style techniques. The vulnerabilities impact Apache HTTP Server's mod_http2 module, which is crucial for handling HTTP/2 requests. Users are advised to update to the patched versions to mitigate these risks. The vulnerabilities could lead to significant service disruptions if exploited. The advisory emphasizes the importance of applying the updates promptly to safeguard systems.
Key Points: • Oracle Linux 10 mod_http2 has multiple DoS vulnerabilities disclosed. • CVE-2026-49975 allows remote DoS via compression bomb and Slowloris-style attacks. • Users are urged to apply patches immediately to prevent service disruptions.