NullPointerException in mod_cluster's AdvertiseListenerImpl Affects Red Hat
CVE-2026-76166
4.3MEDIUM
What is CVE-2026-76166?
A vulnerability exists in mod_cluster's AdvertiseListenerImpl, where a crafted UDP multicast datagram lacking specific headers leads to a silent NullPointerException. This exception is uncaught by the worker thread's handler, causing the advertise listener thread to crash indefinitely. Although the isListening() function continues to affirm that the service is operational, the component fails until the server is restarted. This issue affects all deployments configured with a security key, as it occurs before any AdvertiseSecurityKey validations.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Kien Pham (Ninh Thanh Cyber Security (NTCS)) and Ta Duc Thien (Ninh Thanh Cyber Security (NTCS)) for reporting this issue.