Issued at: 2026-06-05
Updated at: 2026-06-05
Synopsis
Moderate: mod_http2 security update
Description
The mod_h2 Apache httpd module implements the HTTP2 protocol (h2+h2c) on top of libnghttp2 for httpd 2.4 servers.
Security Fix(es):
* httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected products
Rocky Linux 10 aarch64
Rocky Linux 10 ppc64le
Rocky Linux 10 riscv64
Rocky Linux 10 s390x
Rocky Linux 10 x86_64
Fixes
2379343
CVEs
CVE-2025-53020
Affected packages
Rocky Linux 10 aarch64 - AppStream
mod_http2-0:2.0.29-4.el10_2.aarch64.rpm
mod_http2-0:2.0.29-4.el10_2.src.rpm
mod_http2-debuginfo-0:2.0.29-4.el10_2.aarch64.rpm
mod_http2-debugsource-0:2.0.29-4.el10_2.aarch64.rpm
Rocky Linux 10 ppc64le - AppStream
mod_http2-0:2.0.29-4.el10_2.src.rpm
mod_http2-0:2.0.29-4.el10_2.ppc64le.rpm
mod_http2-debuginfo-0:2.0.29-4.el10_2.ppc64le.rpm
mod_http2-debugsource-0:2.0.29-4.el10_2.ppc64le.rpm
Rocky Linux 10 riscv64 - AppStream
mod_http2-0:2.0.29-4.el10_2.src.rpm
Rocky Linux 10 s390x - AppStream
mod_http2-0:2.0.29-4.el10_2.src.rpm
mod_http2-debugsource-0:2.0.29-4.el10_2.s390x.rpm
mod_http2-0:2.0.29-4.el10_2.s390x.rpm
mod_http2-debuginfo-0:2.0.29-4.el10_2.s390x.rpm
Rocky Linux 10 x86_64 - AppStream
mod_http2-0:2.0.29-4.el10_2.src.rpm
mod_http2-0:2.0.29-4.el10_2.x86_64.rpm
mod_http2-debugsource-0:2.0.29-4.el10_2.x86_64.rpm
mod_http2-debuginfo-0:2.0.29-4.el10_2.x86_64.rpm