Critical severity9.1NVD Advisory· Published Mar 14, 2022· Updated Jun 17, 2026
CVE-2022-22721
CVE-2022-22721
Description
If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
80- osv-coords55 versionspkg:rpm/almalinux/mod_luapkg:rpm/almalinux/mod_sessionpkg:rpm/suse/apache2&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/almalinux/httpdpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/almalinux/mod_mdpkg:rpm/opensuse/apache2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/apache2&distro=HPE%20Helion%20OpenStack%208pkg:rpm/almalinux/httpd-corepkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2015.3pkg:rpm/almalinux/mod_sslpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:bitnami/apachepkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/apache2&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/almalinux/httpd-develpkg:rpm/almalinux/httpd-filesystempkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/mod_http2pkg:rpm/almalinux/mod_ldappkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/apache2&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSSpkg:rpm/almalinux/httpd-tools
< 2.4.53-7.el9+ 54 more
- (no CPE)range: < 2.4.53-7.el9
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 1:2.0.8-8.module_el8.6.0+2872+fe0ff7aa
- (no CPE)range: < 2.4.53-1.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.51-35.13.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.53-7.el9
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.51-35.13.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 1:2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.51-35.13.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.53
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.23-29.88.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.33-150000.3.66.1
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 1.15.7-5.module_el8.6.0+2872+fe0ff7aa
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 2.4.51-150200.3.42.1
- (no CPE)range: < 1:2.4.37-51.module_el8.7.0+3281+01e58653
- (no CPE)range: < 2.2.34-70.41.1
- (no CPE)range: < 2.2.34-70.41.1
- (no CPE)range: < 2.4.37-51.module_el8.7.0+3281+01e58653
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: <=2.4.52
- (no CPE)range: Apache HTTP Server 2.4
- (no CPE)range: <=2.4.52
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*range: >=10.15,<10.15.7
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2020-001:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-001:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-002:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-003:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-004:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-005:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-006:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-007:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2021-008:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-001:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-002:*:*:*:*:*:*
- cpe:2.3:o:apple:mac_os_x:10.15.7:security_update_2022-003:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
16- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- seclists.org/fulldisclosure/2022/May/33nvdThird Party Advisory
- seclists.org/fulldisclosure/2022/May/35nvdThird Party Advisory
- seclists.org/fulldisclosure/2022/May/38nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2022/03/14/2nvdMailing ListThird Party Advisory
- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- lists.debian.org/debian-lts-announce/2022/03/msg00033.htmlnvdMailing ListThird Party Advisory
- security.gentoo.org/glsa/202208-20nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20220321-0001/nvdThird Party Advisory
- support.apple.com/kb/HT213255nvdThird Party Advisory
- support.apple.com/kb/HT213256nvdThird Party Advisory
- support.apple.com/kb/HT213257nvdThird Party Advisory
- www.oracle.com/security-alerts/cpujul2022.htmlnvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/nvd
News mentions
0No linked articles in our index yet.