
قواعد الكشف عن CVE-2026-23918 Apache http2 RCE - الاعتماد: stringa.ai, isec.pl
تاريخ النشر: 2026-05-04
CVSSv3: 8.8 (عالي)
النوع: تنفيذ التعليمات البرمجية عن بعد / حرمان الخدمة (Double-Free فساد الذاكرة)
المكون: Apache HTTP Server mod_http2 (h2_mplx.c مسار تنظيف الدفق)
المتأثر: Apache HTTP Server 2.4.66 مع تمكين HTTP/2 وMPM متعدد الخيوط
المراجع:
CVE-2026-23918 هي ثغرة تحرير مزدوج (double-free memory corruption) في تنفيذ بروتوكول HTTP/2 لخادوم Apache HTTP Server 2.4.66، وتؤثر فقط على مسار تنظيف الدفق في الوحدة mod_http2 في h2_mplx.c. تسمح لمهاجم عن بعد غير مصادق بتعطيل عمليات Apache العاملة (حرمان الخدمة) باستخدام اتصال TCP واحد وإطارين من HTTP/2. في ظل ظروف موجودة في الأنظمة المشتقة من Debian وصور Docker الرسمية لـ Apache، يمكن تشكيل التحرير المزدوج إلى تنفيذ تعليمات برمجية عن بعد بالكامل.
تم تأكيد استغلال حرمان الخدمة في البيئة الواقعية. وقد لوحظت عمليات مسح واسعة النطاق على الإنترنت تستهدف نقاط نهاية HTTP/2. تم إثبات قابلية استغلال RCE في بيئات محكومة، على الرغم من عدم وجود دليل على استغلال عام واسع النطاق لـ RCE في الوقت الحالي.
لا يتأثر MPM prefork — تتطلب الثغرة تكوين MPM متعدد الخيوط (worker أو event أو ما شابه). CVE-2026-23918 تؤثر فقط على Apache HTTP Server الإصدار 2.4.66.
Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream
Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup
Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE
c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption
DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption
RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE
> **عدم التماثل الرئيسي:** مسار رفض الخدمة لا يتطلب مهارة في التعامل مع الكومة ويتم استغلاله بنشاط. مسار تنفيذ التعليمات البرمجية عن بُعد يتطلب تقنية عالية ولكنه تم إثباته في ظروف المختبر وسيتم تسليحه بالتأكيد في المستقبل القريب نظرًا لعنوان لوحة النتائج الثابت المقاوم لـ ASLR.
---
## هندسة الكشف
> يشرح هذا القسم سبب اختلاف أدوات الكشف هنا بشكل كبير عن حزمة تصعيد الامتيازات المحلية النموذجية.
كانت ثغرة Copy Fail (CVE-2026-31431) ثغرة **على جانب المضيف، بعد الوصول**. كان المهاجم بحاجة إلى وجود مسبق على النظام. كان الكشف يتم بشكل أساسي على طبقة استدعاء النظام (auditd, Wazuh) مع مسح YARA للنص البرمجي للإثبات على القرص.
أما ثغرة CVE-2026-23918 فهي ثغرة **على جانب الشبكة، قبل الوصول**. يصل الاستغلال كإطارات بروتوكول HTTP/2 عبر الشبكة قبل تشغيل أي كود تطبيق. هذا يحول مجموعة الكشف بشكل كبير:
| الطبقة | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
|---|---|---|
| **الكشف الأساسي** | قواعد استدعاءات النظام في Auditd | قواعد شبكة Suricata |
| **جدار حماية تطبيقات الويب (ModSecurity)** | محدود - لا يستطيع رؤية الاستغلال | ذو صلة - الكشف عن الشذوذ وما بعد الاستغلال |
| **Auditd** | كشف أساسي | كشف النتائج (تعطلات، ما بعد الاستغلال) |
| **YARA** | مسح النص البرمجي للإثبات | مسح القذائف الويب (آثار ما بعد الاستغلال) |
| **نظام كشف التسلل الشبكي** | غير قابل للتطبيق | طبقة كشف من الدرجة الأولى |
| **فحص TLS** | غير متاح | مطلوب لتغطية كاملة لـ Suricata |
القاعدة الأساسية: بالنسبة لثغرات تنفيذ التعليمات البرمجية عن بُعد على مستوى الشبكة، اعمل من الخارج إلى الداخل (شبكة ← جدار حماية تطبيقات الويب ← مضيف). بالنسبة لتصعيد الامتيازات المحلية، اعمل من المضيف إلى الخارج.
---
## حدود الكشف
> **اقرأ هذا قبل نشر أي قواعد.**
**1. TLS يُنهي رؤية HTTP/2.**
تقدم معظم خوادم Apache في الإنتاج خدمة HTTPS. لا تستطيع Suricata فحص محتويات إطارات HTTP/2 المشفرة بدون تكوين فك تشفير TLS. إذا كان نشر Suricata الخاص بك لا يملك إمكانية الوصول إلى مفاتيح جلسة TLS أو مرآة فك تشفير، فإن القواعد على مستوى الشبكة أدناه ستكتشف فقط:
- HTTP/2 النصي الصريح (h2c) — غير شائع في الإنتاج ولكنه موجود في البيئات الداخلية
- البصمة الشبكية لسلوك اتصال TCP (عدد الاتصالات، أنماط RST على طبقة TCP)
بالنسبة لنشر HTTPS، قم بتمكين فك تشفير TLS في Suricata عبر إعداد `tls-decrypt` وتسجيل مفاتيح الجلسة، أو اعتمد على طبقات جدار حماية تطبيقات الويب (ModSecurity/Coraza) والمضيف (auditd/Wazuh) بدلاً من ذلك.
**2. لا يستطيع ModSecurity حجب مشغل الاستغلال.**
يحدث التحرير المزدوج داخل محلل إطار HTTP/2، قبل تجميع طلب HTTP كامل وتمريره إلى ModSecurity. يرى جدار حماية تطبيقات الويب الطلب فقط بعد اكتمال تحليل الإطارات — عندها قد يكون الضرر قد حدث بالفعل. يتم استخدام ModSecurity في هذه الحزمة للكشف عن الشذوذ وتحديد المعدل واكتشاف ما بعد الاستغلال، وليس كحاجز للمشغل.
**3. MPM prefork غير متأثر.**
إذا كان نشر Apache الخاص بك يستخدم `mpm_prefork_module` (أحادي الخيط)، فإن هذه الثغرة لا تنطبق. يظهر الخلل فقط في وحدات MPM متعددة الخيوط (`mpm_event_module` أو `mpm_worker_module`). تحقق باستخدام `apachectl -V | grep MPM` قبل نشر قواعد قد تنتج نتائج إيجابية خاطئة على خوادم prefork.
**4. يتطلب تنفيذ التعليمات البرمجية عن بُعد مُخصص mmap.**
يتطلب مسار تنفيذ التعليمات البرمجية عن بُعد (وليس مسار رفض الخدمة) مُخصص الذاكرة mmap الخاص بـ APR، وهو الافتراضي على توزيعات Debian المشتقة وصور Docker الرسمية لـ Apache. النشر على RHEL/CentOS الذي يستخدم jemalloc أو malloc النظام لديه خطر أقل لتنفيذ التعليمات البرمجية عن بُعد، لكنه لا يزال عرضة بالكامل لرفض الخدمة.
**5. لا توجد مؤشرات اختراق مستقرة لما بعد الاستغلال حتى الآن.**
لا توجد مؤشرات اختراق منشورة من البائعين لنشاط ما بعد الاستغلال حتى كتابة هذا. قواعد YARA وقواعد auditd التي تستهدف سلوك ما بعد الاستغلال تعتمد على أنماط عامة للقذائف الويب وتصعيد الامتيازات — ستكتشف النتائج الشائعة ولكن ليس حمولة متطورة ومخصصة.
---
## التخفيف الفوري
طبق حسب ترتيب الأولوية. كل إجراء أكثر إزعاجًا من سابقه، لكنه أكثر اكتمالاً.```bash
# Option 1 (Preferred): Upgrade to 2.4.67
# See Patching & Remediation section below
# Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
# In httpd.conf or relevant VirtualHost / site config:
# Remove or comment out: Protocols h2 h2c http/1.1
# Replace with: Protocols http/1.1
# Then:
apachectl configtest && sudo systemctl restart apache2
# Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
sudo a2dismod mpm_event mpm_worker
sudo a2enmod mpm_prefork
apachectl configtest && sudo systemctl restart apache2
# Option 4: Reverse proxy HTTP/2 termination
# If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
# Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
# nginx: proxy_http_version 1.1; (already the default for upstream connections)
# HAProxy: use-server-close + http/1.1 on backend bind
# Verify with: curl -v --http2 https://your-origin-directly
التحقق من التخفيف: بعد تعطيل HTTP/2، تأكد من الأمر التالي:
curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/ # Should return "1.1", not "2" apachectl -M | grep http2 # Should produce no output
احفظها كـ cve-2026-23918.rules وقم بالإشارة إليها من suricata.yaml.
المتطلبات الأساسية:
- Suricata 6.0+ لدعم كلمة
http2.frametype/http2.errorcode(يُوصى بـ Suricata 7.x)- تفعيل
app-layer.protocols.http2.enabled: yesفيsuricata.yaml- تكوين فك تشفير TLS لتغطية HTTPS (انظر قيود الكشف أعلاه)
- تعيين المتغير
$HTTP_SERVERSليشمل مضيفي Apache لديك- SIDs أدناه أمثلة — قم بتعديلها لتناسب سياسة SID المحلية لديك```
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231801; rev:1;)
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
threshold: type both, track by_src, count 10, seconds 30;
classtype:denial-of-service;
reference:cve,2026-23918;
sid:9926231802; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";
flow:established,to_server;
content:"|00 00 04 03 00|"; depth:5; offset:0;
threshold: type both, track by_src, count 5, seconds 30;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231803; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";
flow:established,to_server;
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;
content:"|00 00 04 03|"; distance:0; within:512;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231804; rev:1;)
alert http $HTTP_SERVERS any -> $EXTERNAL_NET any
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";
flow:established,to_client;
http.header; content:"Apache/2.4.66";
classtype:policy-violation;
reference:cve,2026-23918;
sid:9926231805; rev:1;)
alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";
flow:established,to_server;
classtype:trojan-activity;
reference:cve,2026-23918;
sid:9926231806; rev:1;)
### ملاحظات التعديل
بعد النشر في وضع `alert` لمدة 24–48 ساعة، راجع الإصابات في القاعدتين 3 و4 — قد تؤدي عملاء HTTP/2 الشرعيون إلى تفعيل هذه القواعد في بيئات عالية الحركة. إذا كانت القاعدة 1 (طبقة التطبيق) تلتقط إشارات كافية، يمكن نقل القاعدتين 3 و4 إلى درجة خطورة أقل أو إسقاطهما.
بالنسبة لنشر Suricata مع حدود `stream-depth`، تأكد من أن نمط تمهيد HTTP/2 في القاعدة 4 يقع ضمن نطاق الفحص.
---
## تكوين ModSecurity / Coraza
> **المتطلبات الأساسية:**
> - ModSecurity 2.x (`libapache2-mod-security2`) أو [Coraza](https://coraza.io/) (البديل الجاهز للاستبدال، والذي يُصان بنشاط)
> - يُوصى باستخدام OWASP Core Rule Set (CRS) 4.x: [coreruleset.org/installation](https://coreruleset.org/installation/)
> - `SecRuleEngine On` (أو `DetectionOnly` لوضع التسجيل فقط أثناء التعديل الأولي)
### لماذا ModSecurity ذو صلة هنا (ولكنه غير كافٍ)
كما هو موضح في قسم قيود الكشف، لا يستطيع ModSecurity اعتراض مشغل التحرير المزدوج (double-free trigger) لأن الثغرة تعمل على طبقة إطارات HTTP/2. ومع ذلك، يوفر ModSecurity ثلاث طبقات ذات معنى لهذا CVE:
1. **تحديد المعدل (Rate limiting)** — يُبطئ فحص DoS الآلي ويزيد تكلفة هجوم brute-force على رش الكومة (heap spray) لـ RCE.
2. **الكشف بعد الاستغلال (Post-exploitation detection)** — إذا تحقق RCE، سيحاول المهاجم نشر شيل ويب أو تنفيذ أوامر؛ يمكن لـ ModSecurity اكتشاف كليهما.
3. **تسجيل الشذوذ في OWASP CRS (Anomaly scoring)** — قد تُسجل الرؤوس غير الصالحة وأنماط الاتصال المرتبطة بالاستغلال بشكل شاذ تحت مستوى جنون العظمة 2+ (Paranoia Level 2+) في CRS.
### تقوية تكوين Apache (يُطبق جنبًا إلى جنب مع ModSecurity)
أضف إلى `httpd.conf` أو ملف تضمين. هذه توجيهات خاصة بـ Apache، وليست قواعد ModSecurity، لكنها تقلل من سطح الهجوم لـ HTTP/2:```apache
# ============================================================
# CVE-2026-23918 Apache HTTP/2 Hardening Directives
# ============================================================
# Limit concurrent streams per HTTP/2 session.
# The exploit typically uses 1 stream, but limiting sessions
# reduces the rate at which a single client can attempt the trigger.
H2MaxSessionRequests 100
# Restrict H2 stream push (unused surface, reduce complexity)
H2Push Off
# Suppress version information in Server headers.
# Prevents trivial identification of vulnerable 2.4.66 instances.
ServerTokens Prod
ServerSignature Off
# Constrain HTTP/2 window size — reduces memory available for heap spray
H2WindowSize 65535
# If HTTP/2 is not required at all:
# Protocols http/1.1
احفظ هذه القواعد في ملف قواعد ModSecurity المخصص لديك (على سبيل المثال، /etc/modsecurity/cve-2026-23918.conf):```apache
SecAction
"id:9923918001,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR},
setvar:ip.http2_requests=+1,
expirevar:ip.http2_requests=60"
SecRule ip:http2_requests "@gt 30"
"id:9923918002,
phase:1,
deny,
status:429,
log,
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',
tag:'CVE-2026-23918',
tag:'OWASP_CRS/DoS',
severity:'CRITICAL'"
SecAction
"id:9923918003,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR}"
SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"
"id:9923918004,
phase:5,
nolog,
pass,
setvar:ip.error_count=+1,
expirevar:ip.error_count=120"
SecRule ip:error_count "@gt 20"
"id:9923918005,
phase:1,
log,
pass,
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',
tag:'CVE-2026-23918',
severity:'WARNING'"
SecRule REQUEST_BODY
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"
"id:9923918010,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Possible web shell command execution in POST body',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule ARGS
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"
"id:9923918011,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"
"id:9923918012,
phase:2,
log,
deny,
status:403,
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule REQUEST_BODY|ARGS
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"
"id:9923918013,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',
tag:'CVE-2026-23918',
tag:'REVERSE_SHELL',
severity:'CRITICAL'"
### توصية ضبط OWASP CRS
للحصول على أعلى إشارة شذوذ دون إنذارات كاذبة مفرطة، قم بنشر CRS عند مستوى البارانويا 2 مع تفعيل تسجيل الشذوذ. ستؤدي سلوكيات الاتصال المحفزة (HTTP/2 غير صحيح مما يؤدي إلى أخطاء الرجوع إلى HTTP/1.x، وإعادة الضبط المتكررة) إلى تراكم نقاط الشذوذ ضمن قواعد CRS 920xxx و921xxx وقد تتجاوز الحد الافتراضي `inbound_anomaly_score_threshold` البالغ 5، مما يولد إنذارات دون قواعد مخصصة.
---
## قواعد Auditd
احفظها كـ `/etc/audit/rules.d/cve-2026-23918.rules`
أعد التحميل باستخدام: `sudo augenrules --load`
> **مبدأ التصميم:** نظرًا لأن مشغل الاستغلال يقع في طبقة تحليل HTTP/2 الخاصة بالشبكة/النواة، لا يمكن لـ auditd اصطياد المشغل نفسه. تكتشف هذه القواعد:
> 1. **نتيجة** استغلال الحرمان من الخدمة (إشارات تعطل عامل Apache)
> 2. **النشاط اللاحق للاستغلال** في حال تحقيق تنفيذ الأوامر عن بُعد (تنفيذ شيل، كتابة ملفات، اتصالات صادرة من قبل مستخدم Apache)```bash
## ============================================================
## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
## ============================================================
## These rules detect the CONSEQUENCES of exploitation, not the
## trigger. The trigger is a network protocol event and is
## detected by Suricata. These rules catch:
## 1. Apache worker process crashes (DoS outcome)
## 2. Shell execution by the web server user (RCE outcome)
## 3. Web root file creation (web shell deployment)
## 4. Outbound network connections by web server process (reverse shell)
##
## Distribution notes for UID values:
## - Debian/Ubuntu: www-data = uid 33
## - RHEL/Rocky/CentOS: apache = uid 48
## Adjust -F uid= values for your distribution. Use `id www-data`
## or `id apache` to confirm the UID on your systems.
## ============================================================
## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
## A double-free that reaches the crash path generates SIGABRT (signal 6).
## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
## termination, which Apache itself triggers on double-free detection.
## Correlate with Apache error log entries (child exited with signal 6).
-a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
-a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt
## --- SIGSEGV monitoring (alternative crash path) ---
## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
## rather than SIGABRT. Both are abnormal for production Apache workers.
-a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
-a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv
## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
## If RCE is achieved via the mmap allocator path, the attacker's payload
## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
## by www-data is anomalous and warrants immediate investigation.
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb
## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh -k cve_2026_23918_rce_shell_rhel
## --- Web root file creation (web shell deployment) ---
## Post-RCE, the most common next step is writing a persistent web shell.
## Monitor web root directories for new file creation and write operations.
## Adjust paths for your DocumentRoot configuration.
-w /var/www/html -p wa -k cve_2026_23918_webroot_write
-w /var/www -p wa -k cve_2026_23918_webroot_write
-w /srv/www -p wa -k cve_2026_23918_webroot_write
-w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write
## --- Outbound network connections by web server user (reverse shell) ---
## Apache workers do not normally initiate outbound TCP connections.
## connect() syscalls by www-data/apache indicate post-exploitation activity.
-a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
-a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel
## --- Apache config and module modification (persistence) ---
## An attacker with RCE may attempt to persist by modifying Apache config
## or dropping a malicious module. Watch for writes to config directories.
-w /etc/apache2 -p wa -k cve_2026_23918_apache_config
-w /etc/httpd -p wa -k cve_2026_23918_apache_config
-w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods
بعد النشر، استخدم الأمر البسيط ausearch التالي للتحقق من تسلسلات التعطل ثم الصدفة:```bash
sudo ausearch -k cve_2026_23918_sigabrt
-k cve_2026_23918_rce_shell_deb
-k cve_2026_23918_rce_shell_rhel
-k cve_2026_23918_webroot_write
--start yesterday -i
sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="
---
## قواعد Wazuh
احفظ كملف قواعد مخصص (مثل `/var/ossec/etc/rules/local_rules.xml`).
> **المتطلبات الأساسية:**
> - قواعد Auditd المنشورة أعلاه ومفكك تشفير Wazuh auditd نشط
> - سجل أخطاء Apache (`/var/log/apache2/error.log` أو `/var/log/httpd/error_log`) مضاف إلى الملفات المراقبة من Wazuh
> - سجل وصول Apache مراقب لأنماط خطأ اتصال HTTP/2```xml
<!-- ==============================================================
CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
Requires:
- auditd rules from cve-2026-23918.rules deployed
- Apache error log monitored by Wazuh agent
============================================================== -->
<!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
<rule id="113001" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigabrt</field>
<description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 10: SIGSEGV variant crash path -->
<rule id="113002" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigsegv</field>
<description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
<rule id="113003" level="14" frequency="3" timeframe="60">
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
<!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
<rule id="113004" level="15">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
<group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
</rule>
<!-- Level 14 CRITICAL: Web shell written to web root -->
<rule id="113005" level="14">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_webroot_write</field>
<description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
<group>cve,rce,webshell,apache,</group>
</rule>
<!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
<rule id="113006" level="13">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
<group>cve,rce,reverse_shell,apache,</group>
</rule>
<!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
<rule id="113007" level="14">
<if_matched_sid>113004</if_matched_sid>
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
<group>cve,rce,reverse_shell,apache,high_confidence,</group>
</rule>
<!-- Level 12: Apache config modified (persistence attempt) -->
<rule id="113008" level="12">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
<description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
<group>cve,rce,persistence,apache,</group>
</rule>
<!-- Level 10: Apache error log — child process crash (log-based correlation) -->
<!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
<rule id="113009" level="10">
<decoded_as>apache-errorlog</decoded_as>
<match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
<description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
<rule id="113010" level="13">
<if_matched_sid>113009</if_matched_sid>
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
احفظ باسم cve_2026_23918.yar
ملاحظة هامة حول النطاق: على عكس Copy Fail (CVE-2026-31431)، لا يمكن لـ YARA اكتشاف مشغل الاستغلال لهذه الثغرة. المشغل هو إطارين HTTP/2 خام مرسلين عبر اتصال شبكي — لا يوجد نص برمجي أو ملف لفحصه. تستهدف قواعد YARA أدناه:
- قذائف الويب ما بعد الاستغلال التي قد تُنشر بعد نجاح RCE
- أوامر القشرة العكسية ذات السطر الواحد والحمولات المشفرة في ملفات يمكن الوصول إليها عبر الويب
- أداة الاستغلال نفسها إذا كانت موجودة على مضيف وسيط أو خادم هجوم وسيط
نطاق الفحص الموصى به: أدلة جذر الويب (
/var/www/،/srv/www/)، أدلة Apache المؤقتة (/tmp/،/var/tmp/)، والملفات المنشأة حديثًا والمملوكة للمستخدمwww-dataأوapache.```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"
strings:
$php_open = "<?php" ascii nocase
$php_short = "<?" ascii nocase
// OS command execution functions
$sys = "system(" ascii nocase
$exec = "exec(" ascii nocase
$passthru = "passthru(" ascii nocase
$shell_exec = "shell_exec(" ascii nocase
$popen = "popen(" ascii nocase
$proc_open = "proc_open(" ascii nocase
// Parameter sourcing — required for command injection
$get_param = "$_GET[" ascii
$post_param = "$_POST[" ascii
$req_param = "$_REQUEST[" ascii
$cookie_param = "$_COOKIE[" ascii
$server_param = "$_SERVER[" ascii
// Obfuscation patterns common in web shells
$b64decode = "base64_decode(" ascii nocase
$str_rot13 = "str_rot13(" ascii nocase
$gzinflate = "gzinflate(" ascii nocase
$eval_call = "eval(" ascii nocase
// Common web shell capability strings
$phpinfo = "phpinfo()" ascii nocase
$file_put = "file_put_contents(" ascii nocase
condition:
filesize < 512KB and
(
// Classic command web shell: PHP + execution function + parameter input
($php_open or $php_short) and
any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
any of ($get_param, $post_param, $req_param, $cookie_param)
)
or
(
// Obfuscated web shell: eval + decode chain
($php_open or $php_short) and
$eval_call and
any of ($b64decode, $str_rot13, $gzinflate)
)
}
rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"
strings:
// Bash TCP reverse shell
$bash_tcp = "/dev/tcp/" ascii
$bash_rev = "bash -i >&" ascii nocase
// Netcat reverse shell
$nc_e = "nc -e /bin/" ascii nocase
$nc_c = "nc -c /bin/" ascii nocase
$ncat_e = "ncat -e /bin/" ascii nocase
// Python reverse shell
$py_socket = "import socket,subprocess" ascii
$py_pty = "import pty;pty.spawn" ascii
// Perl reverse shell
$perl_rev = "perl -e 'use Socket" ascii
// Common reverse shell via curl/wget pipe to bash
$curl_bash = "curl http" ascii
$wget_bash = "wget -O- http" ascii
$bash_pipe = "|bash" ascii
condition:
filesize < 1MB and
(
($bash_tcp and $bash_rev)
or ($nc_e or $nc_c or $ncat_e)
or ($py_socket and $py_pty)
or $perl_rev
or ($curl_bash and $bash_pipe)
or ($wget_bash and $bash_pipe)
)
}
rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"
strings:
// h2_mplx.c specific identifier from public PoC analysis
$mplx_ref = "h2_mplx_c1_client_rst" ascii
$spurge_ref = "c1_purge_streams" ascii
$stream_ref = "h2_stream_destroy" ascii
// CVE reference strings that appear in PoC tools
$cve_str = "CVE-2026-23918" ascii
$version_target = "Apache/2.4.66" ascii
// HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
// HTTP/2 HEADERS frame header: type=0x01
$h2_headers_frame = { 00 00 ?? 01 }
// HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
$h2_rst_frame = { 00 00 04 03 00 }
// Python h2 library usage (hyper-h2) typical in PoC tools
$hyper_h2 = "import h2" ascii
$h2_connection = "H2Connection" ascii
condition:
(
($mplx_ref or $spurge_ref or $stream_ref)
or
($cve_str and $version_target)
or
($hyper_h2 and $h2_connection and $h2_rst_frame)
)
}
## قالب حدث MISP
احفظ باسم `misp_cve_2026_23918.json` واستورد عبر MISP → Events → Import.
> استبدل عناوين UUID النائبة بعناوين UUID4 مولدة حديثًا قبل الاستيراد.```json
{
"Event": {
"uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
"threat_level_id": "2",
"analysis": "2",
"date": "2026-05-04",
"Attribute": [
{
"type": "vulnerability",
"category": "External analysis",
"to_ids": false,
"uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"comment": "CVE identifier",
"value": "CVE-2026-23918"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
"comment": "Vulnerability description",
"value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
"comment": "Affected component",
"value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
"comment": "RCE precondition",
"value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
"comment": "Fix commit — r1930444",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
"comment": "Fix commit — r1930796",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
"comment": "IoC: HTTP/2 frame trigger sequence",
"value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
"comment": "IoC: RST_STREAM frame bytes (raw)",
"value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
"comment": "IoC: Server response header (vulnerable version)",
"value": "Server: Apache/2.4.66"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
"comment": "Exploitation status",
"value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
"comment": "Immediate mitigation",
"value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
"comment": "Apache official advisory",
"value": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
"comment": "oss-security disclosure",
"value": "https://seclists.org/oss-sec/2026/q2/387"
}
],
"Object": [
{
"name": "vulnerability",
"meta-category": "vulnerability",
"Attribute": [
{
"type": "vulnerability",
"object_relation": "id",
"value": "CVE-2026-23918"
},
{
"type": "cvss-score",
"object_relation": "cvss-score",
"value": "8.8"
},
{
"type": "text",
"object_relation": "summary",
"value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
}
]
}
]
}
}
| الإصدار | الحالة | الإجراء |
|---|---|---|
| 2.4.67 | مصحح | الإصدار المستهدف |
| 2.4.66 | ثغرة |
أوامر تحديث التوزيعات:
بعد الترقية، تحقق:```bash apache2 -v # or httpd -v
### ثغرات أخرى تم تصحيحها في 2.4.67
إصدار 2.4.67 يعالج خمس ثغرات. الأكثر أهمية إلى جانب CVE-2026-23918 هي:
- **CVE-2026-24072** — تصعيد الامتيازات عبر معالجة نصوص CGI على ويندوز (يؤثر فقط على نشرات ويندوز)
- **CVE-2026-24081** — تقييم تعبير `mod_rewrite` يسمح لمؤلفي `.htaccess` بقراءة ملفات عشوائية كمستخدم httpd (يؤثر على 2.4.66 والإصدارات الأقدم، تم الإبلاغ عنه في 2026-01-20)
- **CVE-2026-24088** — تجاوز سعة المخزن المؤقت في `mod_proxy_ajp` عبر رسائل AJP مصممة من خلفية AJP ضارة (يؤثر على 2.4.66 والإصدارات الأقدم)
الترقية إلى 2.4.67 تعالج الخمس جميعها في إجراء واحد.
---
## مرجع مؤشرات التسوية الرئيسية
| المؤشر | القيمة | مستوى الثقة | ملاحظات |
|---|---|---|---|
| الإصدار المتأثر | `Apache/2.4.66` في رأس الخادم | **عالي** | الوجود وحده يشير إلى التعرض |
| نوع إطار HTTP/2 | RST_STREAM (0x03) مع رمز خطأ غير صفري | متوسط | أخطاء الاتصال الشرعية تنتج نفس الشيء |
| نمط بايت الإطار | `00 00 04 03 00` (رأس RST_STREAM) | متوسط | عند الدمج مع العتبة = عالي |
| عتبة فيضان RST | >10 RST_STREAM/خطأ غير صفري من نفس المصدر خلال 30 ثانية | **عالي** | متسق مع أدوات رفض الخدمة المنتشرة |
| SIGABRT على عامل Apache | إشارة 6 مرسلة إلى PID `httpd`/`apache2` | **عالي** | العمال العاديون لا ينهون |
| تنفيذ شل بواسطة www-data | `execve()` من bash/sh بواسطة uid 33 أو 48 | **حرج** | يشير بقوة إلى RCE |
| اتصال صادر بواسطة مستخدم Apache | `connect()` بواسطة uid 33 أو 48 إلى IP خارجي | **حرج** | يشير بقوة إلى شل عكسية |
| إنشاء ملف ويب في جذر الويب | ملفات `.php`/`.py`/`.sh` جديدة مكتوبة تحت `/var/www` | **عالي** | قد يشير إلى نشر شل ويب |
| نوع MPM | `mpm_prefork` | غير قابل للتطبيق — **غير متأثر** | تحقق باستخدام `apachectl -V \| grep MPM` |
| شرط مسبق لـ RCE | مخصص ذاكرة APR mmap | سياقي | افتراضي على Debian/Ubuntu؛ ليس افتراضيًا على RHEL |
---
*حزمة الكشف محفوظة تجاه تنبيهات أمان خادم Apache HTTP على [httpd.apache.org/security](https://httpd.apache.org/security/). إذا لاحظت متغيرات استغلال أو أنماط ما بعد الاستغلال غير مغطاة بهذه القواعد، يرجى فتح مشكلة.*
| الترقية فورًا |
| 2.4.65 والإصدارات الأقدم | غير متأثر بهذا الخلل المحدد | قد تكون هناك ثغرات معروفة أخرى — راجع الإشعار |
| التوزيعة | الأمر |
|---|
| Ubuntu / Debian | sudo apt-get update && sudo apt-get upgrade apache2 |
| RHEL / Rocky / AlmaLinux | sudo dnf update httpd |
| Amazon Linux | sudo dnf update httpd |
| SUSE / openSUSE | sudo zypper update apache2 |
| Arch Linux | sudo pacman -Syu |