Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:34109

Опубликовано: 07 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: httpd security, bug fix, and enhancement update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)

  • httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)

  • httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)

  • httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)

  • httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)

  • httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)

  • httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)

Bug Fix(es) and Enhancement(s):

  • address Moderate severity issues from httpd 2.4.68 [rhel-10.2.z] (JIRA:Rocky Linux-184518)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
httpdx86_6413.el10_2.4httpd-2.4.63-13.el10_2.4.x86_64.rpm
httpd-toolsx86_6413.el10_2.4httpd-tools-2.4.63-13.el10_2.4.x86_64.rpm
mod_sessionx86_6413.el10_2.4mod_session-2.4.63-13.el10_2.4.x86_64.rpm
httpd-filesystemnoarch13.el10_2.4httpd-filesystem-2.4.63-13.el10_2.4.noarch.rpm
httpd-develx86_6413.el10_2.4httpd-devel-2.4.63-13.el10_2.4.x86_64.rpm
mod_proxy_htmlx86_6413.el10_2.4mod_proxy_html-2.4.63-13.el10_2.4.x86_64.rpm
mod_ldapx86_6413.el10_2.4mod_ldap-2.4.63-13.el10_2.4.x86_64.rpm
mod_sslx86_6413.el10_2.4mod_ssl-2.4.63-13.el10_2.4.x86_64.rpm
httpd-corex86_6413.el10_2.4httpd-core-2.4.63-13.el10_2.4.x86_64.rpm
mod_luax86_6413.el10_2.4mod_lua-2.4.63-13.el10_2.4.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
9 дней назад

Important: httpd security, bug fix, and enhancement update

oracle-oval
11 дней назад

ELSA-2026-41906: httpd security, bug fix, and enhancement update (IMPORTANT)

suse-cvrf
около 1 месяца назад

Security update for apache2

oracle-oval
15 дней назад

ELSA-2026-34109: httpd security, bug fix, and enhancement update (IMPORTANT)

rocky
9 дней назад

Important: httpd:2.4 security, bug fix, and enhancement update