Описание
ELSA-2026-21391: httpd security update (IMPORTANT)
[2.4.62-13.0.1.el9_8.1]
- Replace index.html with Oracle's index page oracle_index.html.
[2.4.62-13.1]
- Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child process crash (CVE-2026-33007)
- Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857)
- Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032)
- Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059)
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
httpd
2.4.62-13.0.1.el9_8.1
httpd-core
2.4.62-13.0.1.el9_8.1
httpd-devel
2.4.62-13.0.1.el9_8.1
httpd-filesystem
2.4.62-13.0.1.el9_8.1
httpd-manual
2.4.62-13.0.1.el9_8.1
httpd-tools
2.4.62-13.0.1.el9_8.1
mod_ldap
2.4.62-13.0.1.el9_8.1
mod_lua
2.4.62-13.0.1.el9_8.1
mod_proxy_html
2.4.62-13.0.1.el9_8.1
mod_session
2.4.62-13.0.1.el9_8.1
mod_ssl
2.4.62-13.0.1.el9_8.1
Oracle Linux x86_64
httpd
2.4.62-13.0.1.el9_8.1
httpd-core
2.4.62-13.0.1.el9_8.1
httpd-devel
2.4.62-13.0.1.el9_8.1
httpd-filesystem
2.4.62-13.0.1.el9_8.1
httpd-manual
2.4.62-13.0.1.el9_8.1
httpd-tools
2.4.62-13.0.1.el9_8.1
mod_ldap
2.4.62-13.0.1.el9_8.1
mod_lua
2.4.62-13.0.1.el9_8.1
mod_proxy_html
2.4.62-13.0.1.el9_8.1
mod_session
2.4.62-13.0.1.el9_8.1
mod_ssl
2.4.62-13.0.1.el9_8.1