Sploitus

Exploit for Detections

kitploit · 2026-09-03

Exploit Code

MARKDOWN1074 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-INSOMNISEC-DETECTIONS-CVE-2026-23918
# MOVING TO: https://github.com/insomnisec/public_cve_detections

# FOR BETTER LONG TERM MANAGEMENT OF DETECTION PUBLICATIONS

# THIS REPO WILL BE REMOVED IN JUNE 2026

# PLEASE USE THE OTHER REPO GOING FORWARD

# CVE-2026-23918 «Apache HTTP/2 Double-Free» — пакет обнаружения и реагирования

**Опубликовано:** 2026-05-04  
**CVSSv3:** 8.8 (High)  
**Тип:** Удаленное выполнение кода / Отказ в обслуживании (Double-Free повреждение памяти)  
**Компонент:** Apache HTTP Server `mod_http2` (путь очистки потоков `h2_mplx.c`)  
**Подвержены:** Apache HTTP Server 2.4.66 с включенным HTTP/2 и многопоточным MPM  
**Ссылки:**

  * Рекомендации по безопасности Apache HTTP Server
  * Раскрытие oss-security
  * Технический анализ от Hadrian
  * Освещение insomnisec



* * *

## Содержание

  1. Краткое описание уязвимости
  2. Как работает эксплойт
  3. Архитектура обнаружения — чем этот пакет отличается от пакетов для LPE
  4. Ограничения обнаружения
  5. Немедленное смягчение
  6. Правила Suricata
  7. Конфигурация ModSecurity / Coraza
  8. Правила Auditd
  9. Правила Wazuh
  10. Правила YARA
  11. Шаблон события MISP
  12. Патчи и исправление
  13. Основные IoC для справки



* * *

## Краткое описание уязвимости

CVE-2026-23918 — это уязвимость двойного освобождения памяти (double-free) в реализации протокола HTTP/2 в Apache HTTP Server версии 2.4.66, затрагивающая только путь очистки потоков модуля `mod_http2` в `h2_mplx.c`. Она позволяет неаутентифицированному удаленному злоумышленнику вызвать аварийное завершение рабочих процессов Apache (отказ в обслуживании) с помощью одного TCP-соединения и двух HTTP/2-фреймов. В условиях, присутствующих в системах на базе Debian и официальных Docker-образах Apache, двойное освобождение можно превратить в полноценное удаленное выполнение кода.

Эксплуатация для DoS подтверждена в реальных атаках. Наблюдаются масштабные интернет-сканирования, нацеленные на HTTP/2-конечные точки. Эксплойт для RCE доказал свою жизнеспособность в контролируемых средах, хотя на данный момент нет свидетельств широкой публичной эксплуатации для RCE.

MPM prefork не подвержен — уязвимость требует многопоточной конфигурации MPM (worker, event или аналогичной). CVE-2026-23918 затрагивает только Apache HTTP Server версии 2.4.66.

* * *

## Как работает эксплойт```

Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream

Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup

Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE

c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption

DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption

RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE

root@kitploit:~
    
    
    > **Ключевая асимметрия:** Путь DoS не требует навыков работы с кучей и активно эксплуатируется. Путь RCE технически сложен, но был продемонстрирован в лабораторных условиях и почти наверняка будет превращён в оружие в ближайшем будущем, учитывая фиксированный адрес scoreboard, устойчивый к ASLR.
    
    ---
    
    ## Архитектура обнаружения
    
    > В этом разделе объясняется, почему инструментарий для обнаружения здесь существенно отличается от типичного пакета для локального повышения привилегий.
    
    Copy Fail (CVE-2026-31431) была **хостовой уязвимостью, доступной после атаки**. Злоумышленнику требовалось уже присутствовать в системе. Обнаружение в основном происходило на уровне системных вызовов (auditd, Wazuh) с YARA-сканированием PoC-скрипта на диске.
    
    CVE-2026-23918 — это **сетевая уязвимость, доступная до атаки**. Эксплойт поступает в виде фреймов протокола HTTP/2 по сети до того, как выполняется какой-либо прикладной код. Это существенно меняет стек обнаружения:
    
    | Layer | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
    |---|---|---|
    | **Первичное обнаружение** | Правила auditd для системных вызовов | Сетевые правила Suricata |
    | **WAF (ModSecurity)** | Ограниченно — не видит эксплойт | Актуально — аномалии + пост-эксплойт |
    | **Auditd** | Основное обнаружение | Обнаружение последствий (сбои, пост-эксплойт) |
    | **YARA** | Сканирует PoC-скрипт | Сканирует веб-шеллы (артефакты пост-эксплойта) |
    | **Сетевые IDS** | Не применимо | Основной слой обнаружения |
    | **TLS-инспекция** | Н/П | Требуется для полного покрытия Suricata |
    
    Эмпирическое правило: для RCE на сетевом уровне работайте снаружи внутрь (сеть → WAF → хост). Для локального повышения привилегий — от хоста наружу.
    
    ---
    
    ## Ограничения обнаружения
    
    > **Прочитайте это перед развёртыванием любых правил.**
    
    **1. TLS прекращает видимость HTTP/2.**
    Большинство промышленных развёртываний Apache используют HTTPS. Suricata не может проверять содержимое зашифрованных фреймов HTTP/2 без настроенной дешифрации TLS. Если ваше развёртывание Suricata не имеет доступа к ключам сессии TLS или зеркалу дешифрации, приведённые ниже правила сетевого уровня будут перехватывать только:
    - HTTP/2 в открытом виде (h2c) — редко встречается в продакшне, но присутствует во внутренних средах;
    - Сетевую сигнатуру поведения TCP-соединения (количество соединений, шаблоны RST на уровне TCP).
    
    Для развёртываний HTTPS включите дешифрацию TLS в Suricata через настройку `tls-decrypt` и журналирование ключей сессии, либо полагайтесь вместо этого на WAF (ModSecurity/Coraza) и хостовые слои (auditd/Wazuh).
    
    **2. ModSecurity не может заблокировать триггер эксплойта.**
    Double-free происходит внутри парсера фреймов HTTP/2, до того как полный HTTP-запрос будет собран и передан ModSecurity. WAF видит запрос только после завершения парсинга фреймов — к этому моменту повреждение уже может произойти. ModSecurity в этом пакете используется для обнаружения аномалий, ограничения скорости и детектирования пост-эксплуатации, а не как блокиратор триггера.
    
    **3. MPM prefork не подвержен уязвимости.**
    Если ваше развёртывание Apache использует `mpm_prefork_module` (однопоточный), эта уязвимость не применяется. Ошибка проявляется только в многопоточных MPM (`mpm_event_module` или `mpm_worker_module`). Проверьте с помощью `apachectl -V | grep MPM` перед развёртыванием правил, которые могут давать ложные срабатывания на серверах с prefork.
    
    **4. RCE требует аллокатора mmap.**
    Путь RCE (не путь DoS) требует mmap-аллокатора APR, который используется по умолчанию в дистрибутивах на основе Debian и официальных Docker-образах Apache. Развёртывания на RHEL/CentOS, использующие jemalloc или системный malloc, имеют сниженный риск RCE, но всё ещё полностью уязвимы к DoS.
    
    **5. Стабильных IoC для пост-эксплуатации пока нет.**
    На данный момент не опубликовано ни одного вендорского IoC для пост-эксплуатационной активности. Правила YARA и auditd, нацеленные на поведение после эксплуатации, основаны на общих шаблонах веб-шеллов и повышения привилегий — они перехватят типичные последствия, но не сложную, индивидуальную нагрузку.
    
    ---
    
    ## Немедленное смягчение
    
    Применяйте в порядке предпочтения. Каждое следующее средство более разрушительно, но и более полно.```bash
    # Option 1 (Preferred): Upgrade to 2.4.67
    # See Patching & Remediation section below
    
    # Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
    # In httpd.conf or relevant VirtualHost / site config:
    #   Remove or comment out:  Protocols h2 h2c http/1.1
    #   Replace with:           Protocols http/1.1
    # Then:
    apachectl configtest && sudo systemctl restart apache2
    
    # Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
    sudo a2dismod mpm_event mpm_worker
    sudo a2enmod mpm_prefork
    apachectl configtest && sudo systemctl restart apache2
    
    # Option 4: Reverse proxy HTTP/2 termination
    # If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
    # Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
    #   nginx: proxy_http_version 1.1; (already the default for upstream connections)
    #   HAProxy: use-server-close + http/1.1 on backend bind
    # Verify with: curl -v --http2 https://your-origin-directly
    

> **Проверьте ваше смягчение:** После отключения HTTP/2 убедитесь с помощью:
> 
> root@kitploit:~
>     
>     
>     curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/
>     # Should return "1.1", not "2"
>     apachectl -M | grep http2
>     # Should produce no output
>     

* * *

## Правила Suricata

Сохраните как `cve-2026-23918.rules` и укажите в `suricata.yaml`.

> **Предварительные требования:**
> 
>   * Suricata 6.0+ для поддержки ключевых слов `http2.frametype` / `http2.errorcode` (рекомендуется Suricata 7.x)
>   * `app-layer.protocols.http2.enabled: yes` в `suricata.yaml`
>   * Настроено расшифрование TLS для покрытия HTTPS (см. Ограничения обнаружения выше)
>   * Переменная `$HTTP_SERVERS` должна содержать ваши хосты Apache
>   * SID ниже являются примерами — измените в соответствии с вашей локальной политикой SID```
> 


# =============================================================

# CVE-2026-23918 Apache HTTP/2 Double-Free — Suricata Rules

# =============================================================

# Rule overview:

# 9926231801 — HTTP/2 RST_STREAM with non-zero error code (app layer, high fidelity)

# 9926231802 — RST_STREAM flood threshold (DoS scanning pattern)

# 9926231803 — Raw HTTP/2 RST_STREAM frame detection (h2c / non-TLS fallback)

# 9926231804 — HEADERS+RST rapid sequence targeting HTTP/2 port (behavioral)

# 9926231805 — Apache worker crash signal (host-network correlation)

# 9926231806 — Outbound connection from Apache user post-RCE (lateral movement)

# =============================================================

# \--- Rule 1: HTTP/2 RST_STREAM with non-zero error code (app layer) ---

# Requires: Suricata HTTP/2 app layer parsing, TLS decryption for HTTPS

# This is the highest-fidelity rule — targets the exact protocol condition that

# triggers the double-free. RST_STREAM with error code 0 (NO_ERROR) is normal

# and common; any non-zero error code in the early-reset context is suspicious.

# Expected false positives: legitimate HTTP/2 connection errors (network issues,

# client bugs). Tune threshold if noisy in your environment.

alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any   
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";   
flow:established,to_server;   
http2.frametype:3;   
http2.errorcode:!0;   
classtype:web-application-attack;   
reference:cve,2026-23918;   
sid:9926231801; rev:1;)

# \--- Rule 2: RST_STREAM flood threshold (active DoS/scan pattern) ---

# Triggers after 10 RST_STREAM frames with non-zero error code from one source

# within 30 seconds. This matches the confirmed in-the-wild DoS scanning behavior.

# Lower threshold (e.g., count 5) for higher sensitivity in low-traffic environments.

alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any   
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";   
flow:established,to_server;   
http2.frametype:3;   
http2.errorcode:!0;   
threshold: type both, track by_src, count 10, seconds 30;   
classtype:denial-of-service;   
reference:cve,2026-23918;   
sid:9926231802; rev:1;)

# \--- Rule 3: Raw RST_STREAM frame detection (h2c cleartext / TLS fallback) ---

# Matches the raw HTTP/2 RST_STREAM frame header bytes in cleartext traffic.

# HTTP/2 RST_STREAM frame: 3-byte length (0x000004) | type (0x03) | flags (0x00)

# This does NOT require app-layer HTTP/2 parsing and catches h2c (non-TLS) traffic.

# Higher false positive rate than Rule 1 — use threshold in production.

# For h2c on non-standard ports, adjust destination ports accordingly.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]   
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";   
flow:established,to_server;   
content:"|00 00 04 03 00|"; depth:5; offset:0;   
threshold: type both, track by_src, count 5, seconds 30;   
classtype:web-application-attack;   
reference:cve,2026-23918;   
sid:9926231803; rev:1;)

# \--- Rule 4: HTTP/2 connection preface followed by rapid RST (behavioral) ---

# HTTP/2 client preface begins with "PRI * HTTP/2.0\r\n\r\nSM\r\n\r\n".

# Matching this followed by a rapid close is consistent with DoS scanning tooling

# that establishes a connection, sends the trigger, and moves to the next target.

# Most useful on cleartext h2c; for HTTPS this requires TLS decryption.

alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]   
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";   
flow:established,to_server;   
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;   
content:"|00 00 04 03|"; distance:0; within:512;   
classtype:web-application-attack;   
reference:cve,2026-23918;   
sid:9926231804; rev:1;)

# \--- Rule 5: Apache version string exposure (scanner pre-targeting) ---

# Attackers actively scanning for vulnerable Apache 2.4.66 servers will often

# trigger a version-identifying response. Alert on Apache/2.4.66 in server headers.

# Useful for identifying which of your servers are exposed AND being actively scanned.

# Note: ServerTokens Prod in Apache config suppresses the version string (recommended).

alert http $HTTP_SERVERS any -> $EXTERNAL_NET any   
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";   
flow:established,to_client;   
http.header; content:"Apache/2.4.66";   
classtype:policy-violation;   
reference:cve,2026-23918;   
sid:9926231805; rev:1;)

# \--- Rule 6: Suspicious outbound connection from web server process port ---

# Post-RCE, an attacker will likely establish a reverse shell or exfiltrate data.

# This rule detects NEW outbound TCP connections originating FROM HTTP server ports

# to external destinations, which is anomalous for legitimate Apache behavior.

# Tune $HOME_NET and $HTTP_SERVERS to avoid false positives on proxy configurations.

# This rule pairs with the auditd rule monitoring www-data/apache outbound connects.

alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]   
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";   
flow:established,to_server;   
classtype:trojan-activity;   
reference:cve,2026-23918;   
sid:9926231806; rev:1;)

root@kitploit:~
    
    
    ### Примечания по настройке
    
    После развертывания в режиме `alert` в течение 24–48 часов проверьте срабатывания на Правила 3 и 4 — легитимные HTTP/2-клиенты могут вызывать их в средах с высоким трафиком. Если Правило 1 (уровень приложения) улавливает достаточный сигнал, Правила 3 и 4 можно понизить по критичности или отбросить.
    
    Для развертываний Suricata с ограничениями `stream-depth` убедитесь, что шаблон предисловия HTTP/2 в Правиле 4 попадает в окно проверки.
    
    ---
    
    ## Конфигурация ModSecurity / Coraza
    
    > **Предварительные требования:**
    > - ModSecurity 2.x (`libapache2-mod-security2`) или [Coraza](https://coraza.io/) (полноценный преемник, активно поддерживается)
    > - Рекомендуется OWASP Core Rule Set (CRS) 4.x: [coreruleset.org/installation](https://coreruleset.org/installation/)
    > - `SecRuleEngine On` (или `DetectionOnly` для режима только логирования во время начальной настройки)
    
    ### Почему ModSecurity здесь актуален (но недостаточен)
    
    Как отмечено в разделе «Ограничения обнаружения», ModSecurity не может перехватить триггер двойного освобождения, поскольку эксплойт работает на уровне фреймов HTTP/2. Однако ModSecurity предоставляет три значимых слоя ценности для этого CVE:
    
    1. **Ограничение скорости** — замедляет автоматическое DoS-сканирование и увеличивает затраты на подбор RCE heap spray
    2. **Обнаружение после эксплуатации** — если RCE достигнуто, злоумышленник попытается развернуть веб-шелл или выполнить команды; ModSecurity может обнаружить и то, и другое
    3. **Аномальная оценка OWASP CRS** — некорректные заголовки и шаблоны соединений, связанные с эксплуатацией, могут получить аномальную оценку при уровне паранойи CRS 2+
    
    ### Усиление конфигурации Apache (применять вместе с ModSecurity)
    
    Добавьте в `httpd.conf` или включаемый файл. Это директивы Apache, а не правила ModSecurity, но они уменьшают поверхность атаки HTTP/2:```apache
    # ============================================================
    # CVE-2026-23918 Apache HTTP/2 Hardening Directives
    # ============================================================
    
    # Limit concurrent streams per HTTP/2 session.
    # The exploit typically uses 1 stream, but limiting sessions
    # reduces the rate at which a single client can attempt the trigger.
    H2MaxSessionRequests 100
    
    # Restrict H2 stream push (unused surface, reduce complexity)
    H2Push Off
    
    # Suppress version information in Server headers.
    # Prevents trivial identification of vulnerable 2.4.66 instances.
    ServerTokens Prod
    ServerSignature Off
    
    # Constrain HTTP/2 window size — reduces memory available for heap spray
    H2WindowSize 65535
    
    # If HTTP/2 is not required at all:
    # Protocols http/1.1
    

### Правила ModSecurity

Сохраните их в вашем файле пользовательских правил ModSecurity (например, `/etc/modsecurity/cve-2026-23918.conf`):```apache

# ============================================================

# CVE-2026-23918 ModSecurity Detection Rules

# ============================================================

# Rule IDs 9923918xx — adjust range to fit your local policy.

# ============================================================

# Initialize per-IP request counter in the IP collection

SecAction   
"id:9923918001,  
phase:1,  
nolog,  
pass,  
initcol:ip=%{REMOTE_ADDR},  
setvar:ip.http2_requests=+1,  
expirevar:ip.http2_requests=60"

# Rule 01: Rate limit — block IPs sending more than 30 requests per minute

# Tune the threshold to match your expected legitimate traffic volume.

# This catches automated DoS scanning tools that rapidly recycle connections.

SecRule ip:http2_requests "@gt 30"   
"id:9923918002,  
phase:1,  
deny,  
status:429,  
log,  
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',  
tag:'CVE-2026-23918',  
tag:'OWASP_CRS/DoS',  
severity:'CRITICAL'"

# Rule 02: Detect abnormal connection error rates from same IP

# Legitimate clients rarely produce rapid sequences of HTTP errors.

# Repeated 400-level errors suggest exploit scanning or fuzzing.

SecAction   
"id:9923918003,  
phase:1,  
nolog,  
pass,  
initcol:ip=%{REMOTE_ADDR}"

SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"   
"id:9923918004,  
phase:5,  
nolog,  
pass,  
setvar:ip.error_count=+1,  
expirevar:ip.error_count=120"

SecRule ip:error_count "@gt 20"   
"id:9923918005,  
phase:1,  
log,  
pass,  
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',  
tag:'CVE-2026-23918',  
severity:'WARNING'"

# ============================================================

# POST-EXPLOITATION DETECTION

# The following rules detect outcomes of successful RCE:

# web shell deployment and in-request command execution.

# These are NOT specific to CVE-2026-23918 but are the most

# likely post-exploitation patterns given the Apache context.

# ============================================================

# Rule 03: Web shell detection in POST body — command execution patterns

# Catches PHP web shells that use $_GET/$_POST to pass OS commands.

# Note: if you use legitimate PHP applications, tune false positives carefully.

SecRule REQUEST_BODY   
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"   
"id:9923918010,  
phase:2,  
deny,  
status:403,  
log,  
msg:'CVE-2026-23918: Possible web shell command execution in POST body',  
tag:'CVE-2026-23918',  
tag:'WEBSHELL',  
severity:'CRITICAL'"

# Rule 04: Web shell access pattern — direct GET parameter command execution

# Catches requests like: GET /shell.php?cmd=id

# These are the most common web shell interaction patterns.

SecRule ARGS   
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"   
"id:9923918011,  
phase:2,  
deny,  
status:403,  
log,  
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',  
tag:'CVE-2026-23918',  
tag:'WEBSHELL',  
severity:'CRITICAL'"

# Rule 05: PHP web shell upload detection

# Catches multipart file uploads containing PHP code.

# If your application accepts PHP file uploads legitimately, tune carefully.

SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"   
"id:9923918012,  
phase:2,  
log,  
deny,  
status:403,  
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',  
tag:'CVE-2026-23918',  
tag:'WEBSHELL',  
severity:'CRITICAL'"

# Rule 06: Reverse shell patterns in request data

# Catches common reverse shell one-liners often placed in web shells.

SecRule REQUEST_BODY|ARGS   
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"   
"id:9923918013,  
phase:2,  
deny,  
status:403,  
log,  
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',  
tag:'CVE-2026-23918',  
tag:'REVERSE_SHELL',  
severity:'CRITICAL'"

root@kitploit:~
    
    
    ### Рекомендация по настройке OWASP CRS
    
    Для получения наиболее высокого аномального сигнала без чрезмерных ложных срабатываний разверните CRS на уровне Paranoia Level 2 с включенной оценкой аномалий. Поведение, запускающее соединение (некорректный HTTP/2, приводящий к ошибкам отката к HTTP/1.x, повторные сбросы), будет накапливать оценку аномалий по правилам CRS 920xxx и 921xxx и может превысить значение по умолчанию `inbound_anomaly_score_threshold` равное 5, генерируя оповещения без пользовательских правил.
    
    ---
    
    ## Правила auditd
    
    Сохраните как `/etc/audit/rules.d/cve-2026-23918.rules`
    
    Перезагрузите с помощью: `sudo augenrules --load`
    
    > **Принцип разработки:** Поскольку триггер эксплойта находится на уровне сетевого/ядерного разбора HTTP/2, auditd не может перехватить сам триггер. Эти правила обнаруживают:
    > 1. **Результат** DoS-эксплойта (сигналы сбоя рабочих процессов Apache)
    > 2. **Пост-эксплуатационную активность** в случае достижения RCE (выполнение команд оболочки, запись файлов, исходящие соединения от пользователя Apache)```bash
    ## ============================================================
    ## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
    ## ============================================================
    ## These rules detect the CONSEQUENCES of exploitation, not the
    ## trigger. The trigger is a network protocol event and is
    ## detected by Suricata. These rules catch:
    ##   1. Apache worker process crashes (DoS outcome)
    ##   2. Shell execution by the web server user (RCE outcome)
    ##   3. Web root file creation (web shell deployment)
    ##   4. Outbound network connections by web server process (reverse shell)
    ##
    ## Distribution notes for UID values:
    ##   - Debian/Ubuntu: www-data = uid 33
    ##   - RHEL/Rocky/CentOS: apache = uid 48
    ##   Adjust -F uid= values for your distribution. Use `id www-data`
    ##   or `id apache` to confirm the UID on your systems.
    ## ============================================================
    
    ## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
    ## A double-free that reaches the crash path generates SIGABRT (signal 6).
    ## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
    ## termination, which Apache itself triggers on double-free detection.
    ## Correlate with Apache error log entries (child exited with signal 6).
    -a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
    -a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt
    
    ## --- SIGSEGV monitoring (alternative crash path) ---
    ## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
    ## rather than SIGABRT. Both are abnormal for production Apache workers.
    -a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
    -a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv
    
    ## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
    ## If RCE is achieved via the mmap allocator path, the attacker's payload
    ## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
    ## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
    ## by www-data is anomalous and warrants immediate investigation.
    -a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
    -a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh   -k cve_2026_23918_rce_shell_deb
    -a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
    -a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
    -a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb
    
    ## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
    -a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
    -a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh   -k cve_2026_23918_rce_shell_rhel
    
    ## --- Web root file creation (web shell deployment) ---
    ## Post-RCE, the most common next step is writing a persistent web shell.
    ## Monitor web root directories for new file creation and write operations.
    ## Adjust paths for your DocumentRoot configuration.
    -w /var/www/html     -p wa -k cve_2026_23918_webroot_write
    -w /var/www          -p wa -k cve_2026_23918_webroot_write
    -w /srv/www          -p wa -k cve_2026_23918_webroot_write
    -w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write
    
    ## --- Outbound network connections by web server user (reverse shell) ---
    ## Apache workers do not normally initiate outbound TCP connections.
    ## connect() syscalls by www-data/apache indicate post-exploitation activity.
    -a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
    -a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel
    
    ## --- Apache config and module modification (persistence) ---
    ## An attacker with RCE may attempt to persist by modifying Apache config
    ## or dropping a malicious module. Watch for writes to config directories.
    -w /etc/apache2      -p wa -k cve_2026_23918_apache_config
    -w /etc/httpd        -p wa -k cve_2026_23918_apache_config
    -w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods
    

### Соотнесение событий сбоя с сетевой активностью

После развертывания используйте эту однострочную команду `ausearch` для проверки последовательностей сбой-затем-оболочка:```bash

# Find all CVE-2026-23918 related auditd events from the past 24 hours

sudo ausearch -k cve_2026_23918_sigabrt   
-k cve_2026_23918_rce_shell_deb   
-k cve_2026_23918_rce_shell_rhel   
-k cve_2026_23918_webroot_write   
\--start yesterday -i

# Look for www-data process trees that include shell execution

sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="

root@kitploit:~
    
    
    ---
    
    ## Правила Wazuh
    
    Сохраните как файл пользовательских правил (например, `/var/ossec/etc/rules/local_rules.xml`).
    
    > **Предварительные требования:**
    > - Правила Auditd, развернутые выше, и активный декодер Wazuh auditd
    > - Журнал ошибок Apache (`/var/log/apache2/error.log` или `/var/log/httpd/error_log`) добавлен в отслеживаемые файлы Wazuh
    > - Журнал доступа Apache отслеживается на предмет шаблонов ошибок соединения HTTP/2```xml
    <!-- ==============================================================
         CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
         Requires:
           - auditd rules from cve-2026-23918.rules deployed
           - Apache error log monitored by Wazuh agent
         ============================================================== -->
    
    <!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
    <rule id="113001" level="10">
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_sigabrt</field>
        <description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
        <group>cve,denial_of_service,apache,http2,</group>
    </rule>
    
    <!-- Level 10: SIGSEGV variant crash path -->
    <rule id="113002" level="10">
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_sigsegv</field>
        <description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
        <group>cve,denial_of_service,apache,http2,</group>
    </rule>
    
    <!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
    <rule id="113003" level="14" frequency="3" timeframe="60">
        <if_matched_sid>113001</if_matched_sid>
        <description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
        <group>cve,denial_of_service,apache,http2,high_confidence,</group>
    </rule>
    
    <!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
    <rule id="113004" level="15">
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
        <description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
        <group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
    </rule>
    
    <!-- Level 14 CRITICAL: Web shell written to web root -->
    <rule id="113005" level="14">
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_webroot_write</field>
        <description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
        <group>cve,rce,webshell,apache,</group>
    </rule>
    
    <!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
    <rule id="113006" level="13">
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
        <description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
        <group>cve,rce,reverse_shell,apache,</group>
    </rule>
    
    <!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
    <rule id="113007" level="14">
        <if_matched_sid>113004</if_matched_sid>
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
        <description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
        <group>cve,rce,reverse_shell,apache,high_confidence,</group>
    </rule>
    
    <!-- Level 12: Apache config modified (persistence attempt) -->
    <rule id="113008" level="12">
        <if_group>auditd</if_group>
        <field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
        <description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
        <group>cve,rce,persistence,apache,</group>
    </rule>
    
    <!-- Level 10: Apache error log — child process crash (log-based correlation) -->
    <!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
    <rule id="113009" level="10">
        <decoded_as>apache-errorlog</decoded_as>
        <match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
        <description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
        <group>cve,denial_of_service,apache,http2,</group>
    </rule>
    
    <!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
    <rule id="113010" level="13">
        <if_matched_sid>113009</if_matched_sid>
        <if_matched_sid>113001</if_matched_sid>
        <description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
        <group>cve,denial_of_service,apache,http2,high_confidence,</group>
    </rule>
    

* * *

## YARA Rules

Сохраните как `cve_2026_23918.yar`

> **Важное примечание по области применения:** В отличие от Copy Fail (CVE-2026-31431), YARA не может обнаружить триггер эксплуатации этой уязвимости. Триггер представляет собой два необработанных кадра HTTP/2, отправленных по сетевому соединению — скрипта или файла для сканирования не существует. Правила YARA ниже нацелены на:
> 
>   1. **Постэксплуатационные веб-шеллы** , которые могут быть развернуты после успешного RCE
>   2. **Однострочные reverse shell** и закодированные полезные нагрузки в веб-доступных файлах
>   3. **Сам инструмент эксплуатации** , если он присутствует на узле-посреднике или сервере злоумышленника
> 

> 
> **Рекомендуемая область сканирования:** корневые каталоги веб-сервера (`/var/www/`, `/srv/www/`), временные каталоги Apache (`/tmp/`, `/var/tmp/`) и недавно созданные файлы, принадлежащие `www-data` или `apache`.```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"

root@kitploit:~
    
    
    strings:
        $php_open       = "<?php" ascii nocase
        $php_short      = "<?" ascii nocase
    
        // OS command execution functions
        $sys            = "system("       ascii nocase
        $exec           = "exec("         ascii nocase
        $passthru       = "passthru("     ascii nocase
        $shell_exec     = "shell_exec("   ascii nocase
        $popen          = "popen("        ascii nocase
        $proc_open      = "proc_open("    ascii nocase
    
        // Parameter sourcing — required for command injection
        $get_param      = "$_GET["        ascii
        $post_param     = "$_POST["       ascii
        $req_param      = "$_REQUEST["    ascii
        $cookie_param   = "$_COOKIE["     ascii
        $server_param   = "$_SERVER["     ascii
    
        // Obfuscation patterns common in web shells
        $b64decode      = "base64_decode(" ascii nocase
        $str_rot13      = "str_rot13("    ascii nocase
        $gzinflate      = "gzinflate("    ascii nocase
        $eval_call      = "eval("         ascii nocase
    
        // Common web shell capability strings
        $phpinfo        = "phpinfo()"     ascii nocase
        $file_put       = "file_put_contents(" ascii nocase
    
    condition:
        filesize < 512KB and
        (
            // Classic command web shell: PHP + execution function + parameter input
            ($php_open or $php_short) and
            any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
            any of ($get_param, $post_param, $req_param, $cookie_param)
        )
        or
        (
            // Obfuscated web shell: eval + decode chain
            ($php_open or $php_short) and
            $eval_call and
            any of ($b64decode, $str_rot13, $gzinflate)
        )
    

}

rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"

root@kitploit:~
    
    
    strings:
        // Bash TCP reverse shell
        $bash_tcp       = "/dev/tcp/"                   ascii
        $bash_rev       = "bash -i >&"                  ascii nocase
    
        // Netcat reverse shell
        $nc_e           = "nc -e /bin/"                 ascii nocase
        $nc_c           = "nc -c /bin/"                 ascii nocase
        $ncat_e         = "ncat -e /bin/"               ascii nocase
    
        // Python reverse shell
        $py_socket      = "import socket,subprocess"    ascii
        $py_pty         = "import pty;pty.spawn"        ascii
    
        // Perl reverse shell
        $perl_rev       = "perl -e 'use Socket"        ascii
    
        // Common reverse shell via curl/wget pipe to bash
        $curl_bash      = "curl http"                   ascii
        $wget_bash      = "wget -O- http"               ascii
        $bash_pipe      = "|bash"                       ascii
    
    condition:
        filesize < 1MB and
        (
            ($bash_tcp and $bash_rev)
            or ($nc_e or $nc_c or $ncat_e)
            or ($py_socket and $py_pty)
            or $perl_rev
            or ($curl_bash and $bash_pipe)
            or ($wget_bash and $bash_pipe)
        )
    

}

rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"

root@kitploit:~
    
    
    strings:
        // h2_mplx.c specific identifier from public PoC analysis
        $mplx_ref       = "h2_mplx_c1_client_rst"      ascii
        $spurge_ref     = "c1_purge_streams"            ascii
        $stream_ref     = "h2_stream_destroy"           ascii
    
        // CVE reference strings that appear in PoC tools
        $cve_str        = "CVE-2026-23918"              ascii
        $version_target = "Apache/2.4.66"               ascii
    
        // HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
        // HTTP/2 HEADERS frame header: type=0x01
        $h2_headers_frame  = { 00 00 ?? 01 }
        // HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
        $h2_rst_frame      = { 00 00 04 03 00 }
    
        // Python h2 library usage (hyper-h2) typical in PoC tools
        $hyper_h2       = "import h2"                   ascii
        $h2_connection  = "H2Connection"                ascii
    
    condition:
        (
            ($mplx_ref or $spurge_ref or $stream_ref)
            or
            ($cve_str and $version_target)
            or
            ($hyper_h2 and $h2_connection and $h2_rst_frame)
        )
    

}

root@kitploit:~
    
    
    ## Шаблон события MISP
    
    Сохраните как `misp_cve_2026_23918.json` и импортируйте через MISP → Events → Import.
    
    > Замените плейсхолдеры UUID на свежесгенерированные UUID4 перед импортом.```json
    {
        "Event": {
            "uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
            "info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
            "threat_level_id": "2",
            "analysis": "2",
            "date": "2026-05-04",
            "Attribute": [
                {
                    "type": "vulnerability",
                    "category": "External analysis",
                    "to_ids": false,
                    "uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
                    "comment": "CVE identifier",
                    "value": "CVE-2026-23918"
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": false,
                    "uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
                    "comment": "Vulnerability description",
                    "value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": false,
                    "uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
                    "comment": "Affected component",
                    "value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": false,
                    "uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
                    "comment": "RCE precondition",
                    "value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": false,
                    "uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
                    "comment": "Fix commit — r1930444",
                    "value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": false,
                    "uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
                    "comment": "Fix commit — r1930796",
                    "value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": true,
                    "uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
                    "comment": "IoC: HTTP/2 frame trigger sequence",
                    "value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": true,
                    "uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
                    "comment": "IoC: RST_STREAM frame bytes (raw)",
                    "value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": true,
                    "uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
                    "comment": "IoC: Server response header (vulnerable version)",
                    "value": "Server: Apache/2.4.66"
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": true,
                    "uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
                    "comment": "Exploitation status",
                    "value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
                },
                {
                    "type": "text",
                    "category": "Other",
                    "to_ids": false,
                    "uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
                    "comment": "Immediate mitigation",
                    "value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
                },
                {
                    "type": "url",
                    "category": "External analysis",
                    "to_ids": false,
                    "uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
                    "comment": "Apache official advisory",
                    "value": "https://httpd.apache.org/security/vulnerabilities_24.html"
                },
                {
                    "type": "url",
                    "category": "External analysis",
                    "to_ids": false,
                    "uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
                    "comment": "oss-security disclosure",
                    "value": "https://seclists.org/oss-sec/2026/q2/387"
                }
            ],
            "Object": [
                {
                    "name": "vulnerability",
                    "meta-category": "vulnerability",
                    "Attribute": [
                        {
                            "type": "vulnerability",
                            "object_relation": "id",
                            "value": "CVE-2026-23918"
                        },
                        {
                            "type": "cvss-score",
                            "object_relation": "cvss-score",
                            "value": "8.8"
                        },
                        {
                            "type": "text",
                            "object_relation": "summary",
                            "value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
                        }
                    ]
                }
            ]
        }
    }
    

* * *

## Исправление и устранение уязвимости

### Путь обновления

Версия| Статус| Действие  
---|---|---  
2.4.67| **Исправлено**|  Целевая версия  
2.4.66  
  
Команды обновления для дистрибутивов:

После обновления проверьте:```bash apache2 -v # or httpd -v

# Should show: Apache/2.4.67

root@kitploit:~
    
    
    ### Другие CVE, исправленные в 2.4.67
    
    Релиз 2.4.67 устраняет пять CVE. Два наиболее значимых наряду с CVE-2026-23918:
    
    - **CVE-2026-24072** — Повышение привилегий через обработку CGI-скриптов в Windows (затрагивает только развёртывания на Windows)
    - **CVE-2026-24081** — Вычисление выражений `mod_rewrite` позволяет авторам `.htaccess` читать произвольные файлы от пользователя httpd (затрагивает версии 2.4.66 и ранее, сообщено 2026-01-20)
    - **CVE-2026-24088** — Переполнение буфера в куче в `mod_proxy_ajp` через специально созданные AJP-сообщения от вредоносного AJP-бэкенда (затрагивает версии 2.4.66 и ранее)
    
    Обновление до версии 2.4.67 устраняет все пять одним действием.
    
    ---
    
    ## Справочник ключевых IoC
    
    | Индикатор | Значение | Уверенность | Примечания |
    |---|---|---|---|
    | Затронутая версия | `Apache/2.4.66` в заголовке Server | **Высокая** | Само наличие указывает на уязвимость |
    | Тип фрейма HTTP/2 | RST_STREAM (0x03) с ненулевым кодом ошибки | Средняя | Легитимные ошибки соединения дают то же самое |
    | Байтовый шаблон фрейма | `00 00 04 03 00` (заголовок RST_STREAM) | Средняя | В сочетании с порогом = высокая |
    | Порог RST-флуда | >10 RST_STREAM/ненулевая ошибка от одного источника за 30 секунд | **Высокая** | Соответствует инструментам DoS в дикой природе |
    | SIGABRT на рабочем процессе Apache | сигнал 6 отправлен PID процесса `httpd`/`apache2` | **Высокая** | Нормальные рабочие процессы не прерываются |
    | Выполнение оболочки от www-data | `execve()` bash/sh от uid 33 или 48 | **Критическая** | Указывает на RCE |
    | Исходящее соединение от пользователя Apache | `connect()` от uid 33 или 48 к внешнему IP | **Критическая** | Указывает на reverse shell |
    | Создание веб-файлов в корне веб-сервера | Новые `.php`/`.py`/`.sh` записаны в `/var/www` | **Высокая** | Может указывать на развёртывание веб-шелла |
    | Тип MPM | `mpm_prefork` | Н/Д — **не затронут** | Проверьте с помощью `apachectl -V \| grep MPM` |
    | Предусловие RCE | APR mmap-аллокатор | Контекстуально | По умолчанию в Debian/Ubuntu; не по умолчанию в RHEL |
    
    ---
    
    *Пакет обнаружения поддерживается на основе рекомендаций по безопасности Apache HTTP Server на [httpd.apache.org/security](https://httpd.apache.org/security/). Если вы наблюдаете варианты эксплуатации или шаблоны пост-эксплуатации, не охваченные этими правилами, пожалуйста, откройте issue.*