Description
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
Problem types
CWE-401 Missing Release of Memory after Effective Lifetime
Product status
2.4.17 (semver)
Timeline
| 2025-06-18: | reported |
| 2025-06-19: | fix developed |
| 2025-07-07: | 2.4.x revision 1927046 |
Credits
Gal Bar Nahum
References
lists.debian.org/debian-lts-announce/2025/08/msg00009.html
www.openwall.com/lists/oss-security/2025/07/10/10
httpd.apache.org/security/vulnerabilities_24.html