
CVE-2026-23918 Apache http2 RCE の検出ルール - クレジット: stringa.ai, isec.pl
公開日: 2026-05-04
CVSSv3: 8.8 (高)
タイプ: リモートコード実行 / サービス拒否(Double-Free メモリ破損)
コンポーネント: Apache HTTP Server mod_http2(h2_mplx.c ストリームクリーンアップパス)
影響を受けるバージョン: HTTP/2 が有効かつマルチスレッド MPM を使用する Apache HTTP Server 2.4.66
参考情報:
CVE-2026-23918 は、Apache HTTP Server 2.4.66 の HTTP/2 プロトコル実装における二重解放メモリ破損の脆弱性であり、h2_mplx.c 内の mod_http2 モジュールのストリームクリーンアップパスのみに影響します。この脆弱性により、認証されていないリモートの攻撃者が、単一の TCP 接続と 2 つの HTTP/2 フレームを使用して Apache ワーカープロセスをクラッシュ(サービス拒否)させる可能性があります。Debian 派生システムおよび公式 Apache Docker イメージで見られる条件下では、二重解放を完全なリモートコード実行に変えることができます。
DoS の悪用は実際の環境で確認されています。HTTP/2 エンドポイントを標的とした大規模なインターネットスキャンが観測されています。RCE エクスプロイトは管理環境で実現可能であることが証明されていますが、現時点で RCE が広く一般に悪用されているという証拠はありません。
MPM prefork は影響を受けません。この脆弱性にはマルチスレッド MPM 構成(worker、event など)が必要です。CVE-2026-23918 は Apache HTTP Server バージョン 2.4.66 のみに影響します。
Attacker opens HTTP/2 connection to Apache 2.4.66 (mod_http2 loaded, multi-threaded MPM) └─ Sends HTTP/2 HEADERS frame on stream N (opens the stream) └─ Immediately sends RST_STREAM on stream N (non-zero error code) └─ Sent BEFORE the multiplexer has registered the stream
Two nghttp2 callbacks fire in sequence: ├─ on_frame_recv_cb (RST received) → calls h2_mplx_c1_client_rst → m_stream_cleanup └─ on_stream_close_cb (stream closed) → calls h2_mplx_c1_client_rst → m_stream_cleanup
Result: same h2_stream pointer pushed onto spurge[] cleanup array TWICE
c1_purge_streams() iterates spurge[] and calls h2_stream_destroy() on each entry: ├─ First call: valid — frees the stream └─ Second call: DOUBLE-FREE — operates on already-freed memory → heap corruption
DoS path (trivial, in the wild): └─ Heap corruption → SIGABRT in worker process → worker dies → service disruption
RCE path (requires mmap allocator — default on Debian/Ubuntu and official Docker): └─ Attacker places fake h2_stream struct at freed virtual address via mmap reuse └─ Points pool cleanup function pointer to system() └─ Uses Apache scoreboard shared memory (fixed address, ASLR-resistant) as payload container └─ c1_purge_streams() executes system() with attacker-controlled argument → RCE
> **主な非対称性:** DoS パスはヒープ操作スキルを必要とせず、積極的に悪用されています。RCE パスは技術的に要求が高く、実験環境では実証済みですが、スコアボードの ASLR 耐性のある固定アドレスを考慮すると、近い将来ほぼ確実に武器化されるでしょう。
---
## 検出アーキテクチャ
> このセクションでは、この検出ツールが典型的なローカル権限昇格パッケージと大きく異なる理由を説明します。
Copy Fail (CVE-2026-31431) は **ホスト側、アクセス後** の脆弱性でした。攻撃者はシステムに既に存在している必要がありました。検出は主に syscall 層 (auditd, Wazuh) と、ディスク上の PoC スクリプトに対する YARA スキャンにありました。
CVE-2026-23918 は **ネットワーク側、アクセス前** の脆弱性です。エクスプロイトは、アプリケーションコードが実行される前に、HTTP/2 プロトコルフレームとしてネットワーク上から到着します。これにより、検出スタックが大きく変化します:
| 層 | Copy Fail (LPE) | CVE-2026-23918 (RCE) |
|---|---|---|
| **主な検出** | Auditd syscall ルール | Suricata ネットワークルール |
| **WAF (ModSecurity)** | 限定的 — エクスプロイトを認識不可 | 関連あり — 異常 + 事後検出 |
| **Auditd** | コア検出 | 結果検出 (クラッシュ、事後検出) |
| **YARA** | PoC スクリプトをスキャン | Web シェルをスキャン (事後検出の痕跡) |
| **ネットワーク IDS** | 非該当 | 最優先の検出層 |
| **TLS 検査** | N/A | Suricata の完全なカバレッジに必要 |
経験則: ネットワークレベルの RCE の場合は、外側から内側へ (ネットワーク → WAF → ホスト) 作業します。ローカル権限昇格の場合は、ホストから外側に向かって作業します。
---
## 検出の制限
> **ルールを展開する前にこれを読んでください。**
**1. TLS により HTTP/2 の可視性が終了します。**
ほとんどの本番環境の Apache デプロイメントは HTTPS を提供しています。Suricata は、TLS 復号化が設定されていない限り、暗号化された HTTP/2 フレームの内容を検査できません。Suricata のデプロイメントが TLS セッションキーまたは復号化ミラーにアクセスできない場合、以下のネットワークレベルのルールは以下のみをキャッチします:
- クリアテキスト HTTP/2 (h2c) — 本番環境では一般的ではありませんが、内部環境には存在します
- TCP 接続動作のネットワークシグネチャ (接続数、TCP 層での RST パターン)
HTTPS デプロイメントの場合は、`tls-decrypt` 設定とセッションキーログを使用して Suricata の TLS 復号化を有効にするか、代わりに WAF (ModSecurity/Coraza) およびホストベース (auditd/Wazuh) 層に依存してください。
**2. ModSecurity はエクスプロイトトリガーをブロックできません。**
ダブルフリーは、完全な HTTP リクエストが組み立てられて ModSecurity に渡される前に、HTTP/2 フレームパーサー内部で発生します。WAF はフレーム解析完了後のみリクエストを認識します — その時点で損害が既に発生している可能性があります。このパッケージの ModSecurity は、異常検出、レート制限、および事後検出に使用され、トリガーのブロッカーとしては使用されません。
**3. MPM prefork は影響を受けません。**
Apache デプロイメントが `mpm_prefork_module` (シングルスレッド) を使用している場合、この脆弱性は該当しません。このバグはマルチスレッド MPM (`mpm_event_module` または `mpm_worker_module`) でのみ現れます。prefork サーバーで誤検出を発生させるルールを展開する前に、`apachectl -V | grep MPM` で確認してください。
**4. RCE には mmap アロケータが必要です。**
RCE パス (DoS パスではない) には APR の mmap アロケータが必要です。これは Debian 派生ディストリビューションおよび公式の Apache Docker イメージのデフォルトです。jemalloc またはシステム malloc を使用する RHEL/CentOS ベースのデプロイメントでは RCE リスクが軽減されますが、DoS に対しては依然として完全に脆弱です。
**5. 安定した事後検出の IoC はまだありません。**
現時点では、事後検出アクティビティに対するベンダー公開の IoC は存在しません。事後検出動作を対象とした YARA ルールおよび auditd ルールは、一般的な Web シェルおよび権限昇格パターンに基づいています — これらは一般的な結果をキャッチしますが、洗練されたカスタムペイロードはキャッチしません。
---
## 即時緩和策
優先順位の高い順に適用してください。各対策は前のものよりも破壊的ですが、より完全になります。```bash
# Option 1 (Preferred): Upgrade to 2.4.67
# See Patching & Remediation section below
# Option 2: Disable HTTP/2 in Apache config (no reboot required, restart required)
# In httpd.conf or relevant VirtualHost / site config:
# Remove or comment out: Protocols h2 h2c http/1.1
# Replace with: Protocols http/1.1
# Then:
apachectl configtest && sudo systemctl restart apache2
# Option 3: Switch to MPM prefork (eliminates vulnerability entirely — more disruptive)
sudo a2dismod mpm_event mpm_worker
sudo a2enmod mpm_prefork
apachectl configtest && sudo systemctl restart apache2
# Option 4: Reverse proxy HTTP/2 termination
# If nginx, HAProxy, or a CDN is in front of Apache and terminates HTTP/2,
# Apache only receives HTTP/1.1 — confirm your proxy config explicitly:
# nginx: proxy_http_version 1.1; (already the default for upstream connections)
# HAProxy: use-server-close + http/1.1 on backend bind
# Verify with: curl -v --http2 https://your-origin-directly
緩和策の確認: HTTP/2を無効にした後、以下で確認してください:
curl -s -o /dev/null -w "%{http_version}" --http2 http://localhost/ # "1.1" を返すべきであり、"2" ではありません apachectl -M | grep http2 # 出力はありません
cve-2026-23918.rules として保存し、suricata.yaml から参照します。
前提条件:
http2.frametype/http2.errorcodeキーワードをサポートする Suricata 6.0+ (Suricata 7.x 推奨)suricata.yamlでapp-layer.protocols.http2.enabled: yes- HTTPS カバレッジのためにTLS復号化が設定されていること(上記の検出の制限を参照)
$HTTP_SERVERS変数に Apache ホストが含まれていること- 以下のSIDは例です — ローカルのSIDポリシーに合わせて調整してください```
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM with non-zero error code";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231801; rev:1;)
alert http2 $EXTERNAL_NET any -> $HTTP_SERVERS any
(msg:"CVE-2026-23918 Apache mod_http2 Double-Free - RST_STREAM flood (active DoS/exploit scan)";
flow:established,to_server;
http2.frametype:3;
http2.errorcode:!0;
threshold: type both, track by_src, count 10, seconds 30;
classtype:denial-of-service;
reference:cve,2026-23918;
sid:9926231802; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000,8443]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 RST_STREAM frame detected (cleartext)";
flow:established,to_server;
content:"|00 00 04 03 00|"; depth:5; offset:0;
threshold: type both, track by_src, count 5, seconds 30;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231803; rev:1;)
alert tcp $EXTERNAL_NET any -> $HTTP_SERVERS [80,8080,8000]
(msg:"CVE-2026-23918 Apache mod_http2 - HTTP/2 client preface with rapid RST_STREAM (exploit pattern)";
flow:established,to_server;
content:"PRI * HTTP/2.0|0d 0a 0d 0a|SM|0d 0a 0d 0a|"; depth:24; offset:0;
content:"|00 00 04 03|"; distance:0; within:512;
classtype:web-application-attack;
reference:cve,2026-23918;
sid:9926231804; rev:1;)
alert http $HTTP_SERVERS any -> $EXTERNAL_NET any
(msg:"CVE-2026-23918 Apache 2.4.66 version string in response - vulnerable version exposed";
flow:established,to_client;
http.header; content:"Apache/2.4.66";
classtype:policy-violation;
reference:cve,2026-23918;
sid:9926231805; rev:1;)
alert tcp $HTTP_SERVERS [80,443,8080,8443] -> $EXTERNAL_NET ![$HTTP_PORTS,443,80]
(msg:"CVE-2026-23918 Apache possible post-RCE reverse shell - outbound from web server port";
flow:established,to_server;
classtype:trojan-activity;
reference:cve,2026-23918;
sid:9926231806; rev:1;)
### チューニングノート
`alert` モードで24~48時間デプロイした後、ルール3および4のヒットを確認してください。高トラフィック環境では、正当なHTTP/2クライアントがこれらをトリガーする可能性があります。ルール1(アプリ層)で十分なシグナルをキャッチしている場合は、ルール3と4の重要度を下げるか、削除できます。
Suricataの `stream-depth` 制限を設定しているデプロイメントでは、ルール4のHTTP/2プリフェイスパターンが検査ウィンドウ内に収まるようにしてください。
---
## ModSecurity / Coraza 設定
> **前提条件:**
> - ModSecurity 2.x(`libapache2-mod-security2`)または [Coraza](https://coraza.io/)(ドロップイン後継、活発にメンテナンス中)
> - OWASP Core Rule Set(CRS)4.x推奨: [coreruleset.org/installation](https://coreruleset.org/installation/)
> - `SecRuleEngine On`(初期チューニング中はログのみのモードとして `DetectionOnly`)
### ModSecurityがここで関連する理由(ただし十分ではない)
「検出の制限」セクションで述べたように、ModSecurityはダブルフリーのトリガーをインターセプトできません。なぜなら、エクスプロイトはHTTP/2フレーム層で動作するからです。しかし、ModSecurityはこのCVEに対して3つの有意義な価値のレイヤーを提供します:
1. **レート制限** — 自動化されたDoSスキャンを遅らせ、RCEヒープスプレーのブルートフォースのコストを増加させます
2. **ポストエクスプロイト検出** — RCEが達成された場合、攻撃者はWebシェルを展開したりコマンドを実行しようとします。ModSecurityは両方をキャッチできます
3. **OWASP CRS異常スコアリング** — エクスプロイトに関連する不正なヘッダーや接続パターンは、CRSパラノイアレベル2以上で異常スコアを記録する可能性があります
### Apache設定の強化(ModSecurityと併用)
`httpd.conf` またはインクルードファイルに追加します。これらはModSecurityルールではなくApacheディレクティブですが、HTTP/2の攻撃対象領域を減らします:```apache
# ============================================================
# CVE-2026-23918 Apache HTTP/2 Hardening Directives
# ============================================================
# Limit concurrent streams per HTTP/2 session.
# The exploit typically uses 1 stream, but limiting sessions
# reduces the rate at which a single client can attempt the trigger.
H2MaxSessionRequests 100
# Restrict H2 stream push (unused surface, reduce complexity)
H2Push Off
# Suppress version information in Server headers.
# Prevents trivial identification of vulnerable 2.4.66 instances.
ServerTokens Prod
ServerSignature Off
# Constrain HTTP/2 window size — reduces memory available for heap spray
H2WindowSize 65535
# If HTTP/2 is not required at all:
# Protocols http/1.1
これを ModSecurity カスタムルールファイル (例: /etc/modsecurity/cve-2026-23918.conf) に保存します:```apache
SecAction
"id:9923918001,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR},
setvar:ip.http2_requests=+1,
expirevar:ip.http2_requests=60"
SecRule ip:http2_requests "@gt 30"
"id:9923918002,
phase:1,
deny,
status:429,
log,
msg:'CVE-2026-23918: Rate limit exceeded - possible DoS/exploit scan',
tag:'CVE-2026-23918',
tag:'OWASP_CRS/DoS',
severity:'CRITICAL'"
SecAction
"id:9923918003,
phase:1,
nolog,
pass,
initcol:ip=%{REMOTE_ADDR}"
SecRule RESPONSE_STATUS "@rx ^(4|5)[0-9]{2}"
"id:9923918004,
phase:5,
nolog,
pass,
setvar:ip.error_count=+1,
expirevar:ip.error_count=120"
SecRule ip:error_count "@gt 20"
"id:9923918005,
phase:1,
log,
pass,
msg:'CVE-2026-23918: Elevated error rate from source IP - possible exploit scanning',
tag:'CVE-2026-23918',
severity:'WARNING'"
SecRule REQUEST_BODY
"@rx (?:system|exec|passthru|shell_exec|popen|proc_open)\s*(\s*(?:$_(?:GET|POST|REQUEST|COOKIE)|base64_decode)"
"id:9923918010,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Possible web shell command execution in POST body',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule ARGS
"@rx (?:(?:^|[;&|`])\s*(?:id|whoami|uname|cat\s+/etc|ls\s+/|pwd|wget\s+http|curl\s+http|bash\s+-[ci]|nc\s+-[el]|python[23]?\s+-c|perl\s+-e|ruby\s+-e))"
"id:9923918011,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: OS command injection pattern in request arguments - possible post-exploit web shell',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule FILES_TMPNAMES "@inspectFile /etc/modsecurity/util/php-filter.pm"
"id:9923918012,
phase:2,
log,
deny,
status:403,
msg:'CVE-2026-23918: PHP code detected in file upload - possible web shell deployment',
tag:'CVE-2026-23918',
tag:'WEBSHELL',
severity:'CRITICAL'"
SecRule REQUEST_BODY|ARGS
"@rx (?:bash\s+-i\s+>&?\s*/dev/tcp|/dev/tcp/[0-9]{1,3}.[0-9]{1,3}|nc\s+(?:-e|-c)\s+/bin/(?:bash|sh)|python[23]?\s+-c\s+['"]import\s+socket)"
"id:9923918013,
phase:2,
deny,
status:403,
log,
msg:'CVE-2026-23918: Reverse shell pattern in request - possible post-exploit activity',
tag:'CVE-2026-23918',
tag:'REVERSE_SHELL',
severity:'CRITICAL'"
### OWASP CRS チューニングの推奨
過剰な誤検知を避けつつ最大の異常シグナルを得るには、異常スコアリングを有効にした状態で Paranoia Level 2 の CRS をデプロイしてください。トリガーとなる接続動作(不正な HTTP/2 による HTTP/1.x フォールバックエラー、繰り返されるリセット)は、CRS ルール 920xxx および 921xxx の下で異常スコアを蓄積し、デフォルトの `inbound_anomaly_score_threshold` である 5 を超える可能性があり、カスタムルールなしでアラートを生成します。
---
## Auditd ルール
`/etc/audit/rules.d/cve-2026-23918.rules` として保存
再読み込み: `sudo augenrules --load`
> **設計原則:** エクスプロイトのトリガーはネットワーク/カーネルの HTTP/2 パース層に存在するため、auditd はトリガー自体を捕捉できません。これらのルールは以下を検出します。
> 1. DoS エクスプロイトの**結果**(Apache ワーカークラッシュシグナル)
> 2. RCE が達成された場合の**ポストエクスプロイト活動**(シェルの実行、ファイル書き込み、Apache ユーザーによる外部接続)```bash
## ============================================================
## CVE-2026-23918 Apache HTTP/2 Double-Free — Auditd Rules
## ============================================================
## These rules detect the CONSEQUENCES of exploitation, not the
## trigger. The trigger is a network protocol event and is
## detected by Suricata. These rules catch:
## 1. Apache worker process crashes (DoS outcome)
## 2. Shell execution by the web server user (RCE outcome)
## 3. Web root file creation (web shell deployment)
## 4. Outbound network connections by web server process (reverse shell)
##
## Distribution notes for UID values:
## - Debian/Ubuntu: www-data = uid 33
## - RHEL/Rocky/CentOS: apache = uid 48
## Adjust -F uid= values for your distribution. Use `id www-data`
## or `id apache` to confirm the UID on your systems.
## ============================================================
## --- Apache worker SIGABRT detection (DoS exploitation outcome) ---
## A double-free that reaches the crash path generates SIGABRT (signal 6).
## Monitoring kill() syscalls with a1=6 (SIGABRT) targets abnormal process
## termination, which Apache itself triggers on double-free detection.
## Correlate with Apache error log entries (child exited with signal 6).
-a always,exit -F arch=b64 -S kill -F a1=6 -k cve_2026_23918_sigabrt
-a always,exit -F arch=b32 -S kill -F a1=6 -k cve_2026_23918_sigabrt
## --- SIGSEGV monitoring (alternative crash path) ---
## Depending on heap state, the double-free may produce a SIGSEGV (signal 11)
## rather than SIGABRT. Both are abnormal for production Apache workers.
-a always,exit -F arch=b64 -S kill -F a1=11 -k cve_2026_23918_sigsegv
-a always,exit -F arch=b32 -S kill -F a1=11 -k cve_2026_23918_sigsegv
## --- Shell execution by web server user (RCE outcome - Debian/Ubuntu) ---
## If RCE is achieved via the mmap allocator path, the attacker's payload
## runs as the Apache worker user (www-data on Debian/Ubuntu, uid=33).
## Legitimate Apache does not exec() a shell. Any execve() of bash/sh/dash
## by www-data is anomalous and warrants immediate investigation.
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/bash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/sh -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/bin/dash -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/python3 -k cve_2026_23918_rce_shell_deb
-a always,exit -F arch=b64 -S execve -F uid=33 -F exe=/usr/bin/perl -k cve_2026_23918_rce_shell_deb
## --- Shell execution by web server user (RCE outcome - RHEL/Rocky, uid=48) ---
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/bash -k cve_2026_23918_rce_shell_rhel
-a always,exit -F arch=b64 -S execve -F uid=48 -F exe=/bin/sh -k cve_2026_23918_rce_shell_rhel
## --- Web root file creation (web shell deployment) ---
## Post-RCE, the most common next step is writing a persistent web shell.
## Monitor web root directories for new file creation and write operations.
## Adjust paths for your DocumentRoot configuration.
-w /var/www/html -p wa -k cve_2026_23918_webroot_write
-w /var/www -p wa -k cve_2026_23918_webroot_write
-w /srv/www -p wa -k cve_2026_23918_webroot_write
-w /usr/share/apache2/default-site -p wa -k cve_2026_23918_webroot_write
## --- Outbound network connections by web server user (reverse shell) ---
## Apache workers do not normally initiate outbound TCP connections.
## connect() syscalls by www-data/apache indicate post-exploitation activity.
-a always,exit -F arch=b64 -S connect -F uid=33 -k cve_2026_23918_apache_outbound_deb
-a always,exit -F arch=b64 -S connect -F uid=48 -k cve_2026_23918_apache_outbound_rhel
## --- Apache config and module modification (persistence) ---
## An attacker with RCE may attempt to persist by modifying Apache config
## or dropping a malicious module. Watch for writes to config directories.
-w /etc/apache2 -p wa -k cve_2026_23918_apache_config
-w /etc/httpd -p wa -k cve_2026_23918_apache_config
-w /etc/apache2/mods-enabled -p wa -k cve_2026_23918_apache_mods
デプロイ後、この ausearch ワンライナーを使用して、クラッシュ後のシェルシーケンスを確認します:```bash
sudo ausearch -k cve_2026_23918_sigabrt
-k cve_2026_23918_rce_shell_deb
-k cve_2026_23918_rce_shell_rhel
-k cve_2026_23918_webroot_write
--start yesterday -i
sudo ausearch -k cve_2026_23918_rce_shell_deb --start today -i | grep -A5 "exe="
---
## Wazuh ルール
カスタムルールファイルとして保存してください(例:`/var/ossec/etc/rules/local_rules.xml`)。
> **前提条件:**
> - 上記でデプロイしたAuditdルールとWazuh auditdデコーダがアクティブであること
> - Apacheエラーログ(`/var/log/apache2/error.log` または `/var/log/httpd/error_log`)がWazuhの監視ファイルに追加されていること
> - HTTP/2接続エラーパターンについてApacheアクセスログが監視されていること```xml
<!-- ==============================================================
CVE-2026-23918 Apache HTTP/2 Double-Free — Wazuh Rules
Requires:
- auditd rules from cve-2026-23918.rules deployed
- Apache error log monitored by Wazuh agent
============================================================== -->
<!-- Level 10: Apache worker crash signal (SIGABRT) detected via auditd -->
<rule id="113001" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigabrt</field>
<description>CVE-2026-23918: SIGABRT sent to process — possible Apache worker double-free crash (DoS exploitation)</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 10: SIGSEGV variant crash path -->
<rule id="113002" level="10">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_sigsegv</field>
<description>CVE-2026-23918: SIGSEGV sent to process — possible Apache worker memory corruption crash</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 14 CRITICAL: Multiple worker crashes in short window — active DoS -->
<rule id="113003" level="14" frequency="3" timeframe="60">
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918 CRITICAL: Multiple Apache worker SIGABRT crashes within 60 seconds — active DoS exploitation in progress</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
<!-- Level 15 CRITICAL: Shell execution by web server user — RCE achieved -->
<rule id="113004" level="15">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_rce_shell_deb|cve_2026_23918_rce_shell_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell executed by web server user (www-data/apache) — RCE likely achieved, immediate incident response required</description>
<group>cve,rce,privilege_escalation,apache,http2,high_confidence,</group>
</rule>
<!-- Level 14 CRITICAL: Web shell written to web root -->
<rule id="113005" level="14">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_webroot_write</field>
<description>CVE-2026-23918: File written to web root directory — possible web shell deployment post-RCE</description>
<group>cve,rce,webshell,apache,</group>
</rule>
<!-- Level 13 CRITICAL: Outbound connection by Apache worker process -->
<rule id="113006" level="13">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918: Outbound TCP connection by web server user — possible reverse shell post-RCE</description>
<group>cve,rce,reverse_shell,apache,</group>
</rule>
<!-- Level 14: RCE shell followed by outbound connection (reverse shell confirmed) -->
<rule id="113007" level="14">
<if_matched_sid>113004</if_matched_sid>
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_outbound_deb|cve_2026_23918_apache_outbound_rhel</field>
<description>CVE-2026-23918 CRITICAL: Shell execution AND outbound connection by web server user — reverse shell active</description>
<group>cve,rce,reverse_shell,apache,high_confidence,</group>
</rule>
<!-- Level 12: Apache config modified (persistence attempt) -->
<rule id="113008" level="12">
<if_group>auditd</if_group>
<field name="audit.key">cve_2026_23918_apache_config|cve_2026_23918_apache_mods</field>
<description>CVE-2026-23918: Apache config or module directory modified — possible attacker persistence attempt</description>
<group>cve,rce,persistence,apache,</group>
</rule>
<!-- Level 10: Apache error log — child process crash (log-based correlation) -->
<!-- Requires Apache error log monitored by Wazuh, decoded via apache decoder -->
<rule id="113009" level="10">
<decoded_as>apache-errorlog</decoded_as>
<match>child pid \d+ exit signal Aborted|child process \d+ still did not exit|segmentation fault</match>
<description>CVE-2026-23918: Apache child process crash in error log — possible double-free DoS exploitation</description>
<group>cve,denial_of_service,apache,http2,</group>
</rule>
<!-- Level 13: Multiple Apache child crashes in error log + auditd SIGABRT (high confidence) -->
<rule id="113010" level="13">
<if_matched_sid>113009</if_matched_sid>
<if_matched_sid>113001</if_matched_sid>
<description>CVE-2026-23918: Apache error log crash + auditd SIGABRT — high-confidence active DoS, investigate immediately</description>
<group>cve,denial_of_service,apache,http2,high_confidence,</group>
</rule>
cve_2026_23918.yar として保存
重要なスコープ注意: Copy Fail (CVE-2026-31431) とは異なり、YARA はこの脆弱性のエクスプロイトトリガーを検出できません。トリガーはネットワーク接続を介して送信される2つの生のHTTP/2フレームであり、スキャンするスクリプトやファイルはありません。以下のYARAルールは以下を対象としています:
- RCE成功後に展開される可能性のあるポストエクスプロイトWebシェル
- リバースシェルのワンライナー およびWebアクセス可能なファイル内のエンコードされたペイロード
- エクスプロイトツール自体(ピボットホストや攻撃者のステージングサーバーに存在する場合)
推奨スキャンスコープ: Webルートディレクトリ (
/var/www/,/srv/www/)、Apache一時ディレクトリ (/tmp/,/var/tmp/)、およびwww-dataまたはapacheが所有する最近作成されたファイル。```yara rule CVE_2026_23918_PostExploit_PHP_WebShell { meta: description = "Post-exploitation PHP web shell — possible CVE-2026-23918 outcome" author = "Detection Engineering" reference = "https://insomnisec.com/posts/2026-05-05-cve-2026-23918-apache-http2-rce_v2/" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Not specific to CVE-2026-23918 trigger — detects likely post-exploitation artifacts"
strings:
$php_open = "<?php" ascii nocase
$php_short = "<?" ascii nocase
// OS command execution functions
$sys = "system(" ascii nocase
$exec = "exec(" ascii nocase
$passthru = "passthru(" ascii nocase
$shell_exec = "shell_exec(" ascii nocase
$popen = "popen(" ascii nocase
$proc_open = "proc_open(" ascii nocase
// Parameter sourcing — required for command injection
$get_param = "$_GET[" ascii
$post_param = "$_POST[" ascii
$req_param = "$_REQUEST[" ascii
$cookie_param = "$_COOKIE[" ascii
$server_param = "$_SERVER[" ascii
// Obfuscation patterns common in web shells
$b64decode = "base64_decode(" ascii nocase
$str_rot13 = "str_rot13(" ascii nocase
$gzinflate = "gzinflate(" ascii nocase
$eval_call = "eval(" ascii nocase
// Common web shell capability strings
$phpinfo = "phpinfo()" ascii nocase
$file_put = "file_put_contents(" ascii nocase
condition:
filesize < 512KB and
(
// Classic command web shell: PHP + execution function + parameter input
($php_open or $php_short) and
any of ($sys, $exec, $passthru, $shell_exec, $popen, $proc_open) and
any of ($get_param, $post_param, $req_param, $cookie_param)
)
or
(
// Obfuscated web shell: eval + decode chain
($php_open or $php_short) and
$eval_call and
any of ($b64decode, $str_rot13, $gzinflate)
)
}
rule CVE_2026_23918_PostExploit_ReverseShell_InFile { meta: description = "Reverse shell one-liner in web-accessible file — possible post-RCE persistence" author = "Detection Engineering" cve = "CVE-2026-23918" date = "2026-05-08" severity = "Critical" note = "Scan web directories and /tmp; may also appear in crontabs and rc.local"
strings:
// Bash TCP reverse shell
$bash_tcp = "/dev/tcp/" ascii
$bash_rev = "bash -i >&" ascii nocase
// Netcat reverse shell
$nc_e = "nc -e /bin/" ascii nocase
$nc_c = "nc -c /bin/" ascii nocase
$ncat_e = "ncat -e /bin/" ascii nocase
// Python reverse shell
$py_socket = "import socket,subprocess" ascii
$py_pty = "import pty;pty.spawn" ascii
// Perl reverse shell
$perl_rev = "perl -e 'use Socket" ascii
// Common reverse shell via curl/wget pipe to bash
$curl_bash = "curl http" ascii
$wget_bash = "wget -O- http" ascii
$bash_pipe = "|bash" ascii
condition:
filesize < 1MB and
(
($bash_tcp and $bash_rev)
or ($nc_e or $nc_c or $ncat_e)
or ($py_socket and $py_pty)
or $perl_rev
or ($curl_bash and $bash_pipe)
or ($wget_bash and $bash_pipe)
)
}
rule CVE_2026_23918_ExploitTool_Artifacts { meta: description = "CVE-2026-23918 exploit tool artifacts — for scanning attacker staging hosts or memory dumps" author = "Detection Engineering" reference = "https://hadrian.io/blog/cve-2026-23918-apache-http-server-double-free-rce-in-http-2-implementation" cve = "CVE-2026-23918" date = "2026-05-08" severity = "High" note = "Matches known PoC tool strings — not expected in production Apache environments"
strings:
// h2_mplx.c specific identifier from public PoC analysis
$mplx_ref = "h2_mplx_c1_client_rst" ascii
$spurge_ref = "c1_purge_streams" ascii
$stream_ref = "h2_stream_destroy" ascii
// CVE reference strings that appear in PoC tools
$cve_str = "CVE-2026-23918" ascii
$version_target = "Apache/2.4.66" ascii
// HTTP/2 HEADERS + RST_STREAM frame bytes (common in PoC HTTP/2 libraries)
// HTTP/2 HEADERS frame header: type=0x01
$h2_headers_frame = { 00 00 ?? 01 }
// HTTP/2 RST_STREAM frame header: type=0x03 with payload=4
$h2_rst_frame = { 00 00 04 03 00 }
// Python h2 library usage (hyper-h2) typical in PoC tools
$hyper_h2 = "import h2" ascii
$h2_connection = "H2Connection" ascii
condition:
(
($mplx_ref or $spurge_ref or $stream_ref)
or
($cve_str and $version_target)
or
($hyper_h2 and $h2_connection and $h2_rst_frame)
)
}
---
## MISP イベントテンプレート
`misp_cve_2026_23918.json` として保存し、MISP → イベント → インポート からインポートします。
> インポート前に、プレースホルダーのUUIDを新しく生成したUUID4に置き換えてください。```json
{
"Event": {
"uuid": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
"info": "CVE-2026-23918 Apache mod_http2 Double-Free — Remote DoS and possible RCE",
"threat_level_id": "2",
"analysis": "2",
"date": "2026-05-04",
"Attribute": [
{
"type": "vulnerability",
"category": "External analysis",
"to_ids": false,
"uuid": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
"comment": "CVE identifier",
"value": "CVE-2026-23918"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "c3d4e5f6-a7b8-9012-cdef-012345678902",
"comment": "Vulnerability description",
"value": "Double-free in Apache HTTP Server 2.4.66 mod_http2 h2_mplx.c stream cleanup path. Triggered by HTTP/2 HEADERS frame immediately followed by RST_STREAM with non-zero error code before stream registration. Results in DoS (confirmed in-wild) or RCE (lab-demonstrated) in multi-threaded MPM configurations."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "d4e5f6a7-b8c9-0123-defa-123456789003",
"comment": "Affected component",
"value": "Apache HTTP Server 2.4.66, mod_http2 module, h2_mplx.c — multi-threaded MPM only (event, worker). MPM prefork is NOT affected."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "e5f6a7b8-c9d0-1234-efab-234567890104",
"comment": "RCE precondition",
"value": "RCE requires APR mmap allocator (default on Debian/Ubuntu and official Apache Docker images). Scoreboard at fixed address bypasses ASLR for practical exploitation."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f6a7b8c9-d0e1-2345-fabc-345678901205",
"comment": "Fix commit — r1930444",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930444"
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "a7b8c9d0-e1f2-3456-abcd-456789012306",
"comment": "Fix commit — r1930796",
"value": "https://svn.apache.org/viewvc?view=revision&revision=1930796"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "b8c9d0e1-f2a3-4567-bcde-567890123407",
"comment": "IoC: HTTP/2 frame trigger sequence",
"value": "HTTP/2 HEADERS frame (type=0x01) immediately followed by RST_STREAM (type=0x03) with non-zero error code, same stream ID, before multiplexer stream registration"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "c9d0e1f2-a3b4-5678-cdef-678901234508",
"comment": "IoC: RST_STREAM frame bytes (raw)",
"value": "00 00 04 03 00 [stream_id 4 bytes] [non-zero error code 4 bytes]"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "d0e1f2a3-b4c5-6789-defa-789012345609",
"comment": "IoC: Server response header (vulnerable version)",
"value": "Server: Apache/2.4.66"
},
{
"type": "text",
"category": "Other",
"to_ids": true,
"uuid": "e1f2a3b4-c5d6-7890-efab-890123456710",
"comment": "Exploitation status",
"value": "DoS exploitation confirmed in the wild. RCE demonstrated in lab conditions; widespread weaponization anticipated."
},
{
"type": "text",
"category": "Other",
"to_ids": false,
"uuid": "f2a3b4c5-d6e7-8901-fabc-901234567811",
"comment": "Immediate mitigation",
"value": "Disable mod_http2: remove 'Protocols h2 h2c' from Apache config and restart. Or switch to MPM prefork. Definitive fix: upgrade to Apache HTTP Server 2.4.67."
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "a3b4c5d6-e7f8-9012-abcd-012345678912",
"comment": "Apache official advisory",
"value": "https://httpd.apache.org/security/vulnerabilities_24.html"
},
{
"type": "url",
"category": "External analysis",
"to_ids": false,
"uuid": "b4c5d6e7-f8a9-0123-bcde-123456789013",
"comment": "oss-security disclosure",
"value": "https://seclists.org/oss-sec/2026/q2/387"
}
],
"Object": [
{
"name": "vulnerability",
"meta-category": "vulnerability",
"Attribute": [
{
"type": "vulnerability",
"object_relation": "id",
"value": "CVE-2026-23918"
},
{
"type": "cvss-score",
"object_relation": "cvss-score",
"value": "8.8"
},
{
"type": "text",
"object_relation": "summary",
"value": "Apache mod_http2 double-free via HTTP/2 early reset — remote DoS and possible RCE"
}
]
}
]
}
}
| バージョン | ステータス | アクション |
|---|---|---|
| 2.4.67 | パッチ済み | 対象バージョン |
| 2.4.66 | 脆弱性あり | 直ちにアップグレード |
| 2.4.65 以前 |
ディストリビューション別の更新コマンド:
アップグレード後、以下を確認してください:```bash apache2 -v # or httpd -v
### 2.4.67 で修正されたその他の CVE
2.4.67 リリースでは、5件の CVE に対応しています。CVE-2026-23918 に加えて、特に重要な2件は以下の通りです。
- **CVE-2026-24072** — Windows 上の CGI スクリプト処理における権限昇格(Windows デプロイのみ影響)
- **CVE-2026-24081** — `mod_rewrite` の式評価により、`.htaccess` 作成者が httpd ユーザーとして任意のファイルを読み取ることが可能(2.4.66 以前に影響、2026-01-20 報告)
- **CVE-2026-24088** — 悪意のある AJP バックエンドからの細工された AJP メッセージによる `mod_proxy_ajp` のヒープバッファオーバーフロー(2.4.66 以前に影響)
2.4.67 にアップグレードすることで、これら5件すべてを一度に修正できます。
---
## 主な IoC リファレンス
| 指標 | 値 | 確信度 | 備考 |
|---|---|---|---|
| 影響を受けるバージョン | Server ヘッダーの `Apache/2.4.66` | **高** | 存在自体が露出を示す |
| HTTP/2 フレームタイプ | 非ゼロエラーコードの RST_STREAM (0x03) | 中 | 正当な接続エラーでも同じものが発生 |
| フレームバイトパターン | `00 00 04 03 00` (RST_STREAM ヘッダー) | 中 | しきい値と組み合わせると高 |
| RST フラッドしきい値 | 30秒以内に同一送信元から非ゼロエラーの RST_STREAM が10回超 | **高** | 実環境の DoS ツールと一致 |
| Apache ワーカーでの SIGABRT | `httpd`/`apache2` PID に signal 6 が送信 | **高** | 通常のワーカーは abort しない |
| www-data によるシェル実行 | uid 33 または 48 での `execve()` による bash/sh の実行 | **重大** | RCE を強く示唆 |
| Apache ユーザーによる外部接続 | uid 33 または 48 による外部 IP への `connect()` | **重大** | リバースシェルを強く示唆 |
| Web ルートへの Web ファイル作成 | `/var/www` 以下に新しい `.php`/`.py`/`.sh` が書き込まれる | **高** | Web シェルの展開を示す可能性 |
| MPM タイプ | `mpm_prefork` | N/A — **影響なし** | `apachectl -V \| grep MPM` で確認 |
| RCE の前提条件 | APR mmap アロケーター | 文脈依存 | Debian/Ubuntu ではデフォルト、RHEL ではデフォルトではない |
---
*この検出パッケージは、[httpd.apache.org/security](https://httpd.apache.org/security/) の Apache HTTP Server セキュリティアドバイザリに基づいて維持されています。これらのルールでカバーされていない攻撃の亜種や侵害後のパターンを観測した場合は、Issue を開いてください。*
| この特定のバグの影響を受けません |
| 他の既知のCVEがある可能性があります — 勧告を確認してください |
| ディストリビューション | コマンド |
|---|
| Ubuntu / Debian | sudo apt-get update && sudo apt-get upgrade apache2 |
| RHEL / Rocky / AlmaLinux | sudo dnf update httpd |
| Amazon Linux | sudo dnf update httpd |
| SUSE / openSUSE | sudo zypper update apache2 |
| Arch Linux | sudo pacman -Syu |