Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:41906

Опубликовано: 22 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: httpd security, bug fix, and enhancement update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)

  • Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)

  • httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)

  • httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)

  • httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)

  • httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)

  • httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)

  • httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)

  • httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)

  • httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)

  • httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)

  • httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)

  • httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)

Bug Fix(es) and Enhancement(s):

  • address Moderate severity issues from httpd 2.4.68 [rhel-9.8.z] (JIRA:Rocky Linux-184520)

  • mod_proxy_html regression in CVE-2026-34355 fix [rhel-9.8.z] (JIRA:Rocky Linux-192752)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
httpdx86_6413.el9_8.5httpd-2.4.62-13.el9_8.5.x86_64.rpm
httpd-corex86_6413.el9_8.5httpd-core-2.4.62-13.el9_8.5.x86_64.rpm
httpd-develx86_6413.el9_8.5httpd-devel-2.4.62-13.el9_8.5.x86_64.rpm
httpd-filesystemnoarch13.el9_8.5httpd-filesystem-2.4.62-13.el9_8.5.noarch.rpm
httpd-manualnoarch13.el9_8.5httpd-manual-2.4.62-13.el9_8.5.noarch.rpm
httpd-toolsx86_6413.el9_8.5httpd-tools-2.4.62-13.el9_8.5.x86_64.rpm
mod_ldapx86_6413.el9_8.5mod_ldap-2.4.62-13.el9_8.5.x86_64.rpm
mod_luax86_6413.el9_8.5mod_lua-2.4.62-13.el9_8.5.x86_64.rpm
mod_proxy_htmlx86_6413.el9_8.5mod_proxy_html-2.4.62-13.el9_8.5.x86_64.rpm
mod_sessionx86_6413.el9_8.5mod_session-2.4.62-13.el9_8.5.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
24 дня назад

Important: httpd security, bug fix, and enhancement update

oracle-oval
11 дней назад

ELSA-2026-41906: httpd security, bug fix, and enhancement update (IMPORTANT)

suse-cvrf
около 1 месяца назад

Security update for apache2

oracle-oval
15 дней назад

ELSA-2026-34109: httpd security, bug fix, and enhancement update (IMPORTANT)

rocky
9 дней назад

Important: httpd:2.4 security, bug fix, and enhancement update