Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:42828

Опубликовано: 21 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: httpd:2.4 security, bug fix, and enhancement update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)

  • httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)

  • httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)

  • httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)

  • httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)

  • httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)

  • httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)

  • httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)

  • httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)

Bug Fix(es) and Enhancement(s):

  • mod_proxy_html regression in CVE-2026-34355 fix [rhel-8.10.z] (JIRA:Rocky Linux-192751)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
httpdx86_6465.module+el8.10.0+40206+be2c8a50.8httpd-2.4.37-65.module+el8.10.0+40206+be2c8a50.8.x86_64.rpm
httpdx86_6465.module+el8.10.0+1830+22f0c9e0httpd-2.4.37-65.module+el8.10.0+1830+22f0c9e0.x86_64.rpm
httpdx86_6465.module+el8.10.0+2061+8d03fdec.5httpd-2.4.37-65.module+el8.10.0+2061+8d03fdec.5.x86_64.rpm
httpdx86_6465.module+el8.10.0+40053+5a18018e.7httpd-2.4.37-65.module+el8.10.0+40053+5a18018e.7.x86_64.rpm
httpdx86_6465.module+el8.10.0+1842+4a9649e8.2httpd-2.4.37-65.module+el8.10.0+1842+4a9649e8.2.x86_64.rpm
httpdx86_6465.module+el8.10.0+40197+0231e209.8httpd-2.4.37-65.module+el8.10.0+40197+0231e209.8.x86_64.rpm
httpdx86_6465.module+el8.10.0+40045+6ce8579b.6httpd-2.4.37-65.module+el8.10.0+40045+6ce8579b.6.x86_64.rpm
httpdx86_6465.module+el8.10.0+1840+b070a976.1httpd-2.4.37-65.module+el8.10.0+1840+b070a976.1.x86_64.rpm
httpdx86_6465.module+el8.10.0+1938+3b7755d4.3httpd-2.4.37-65.module+el8.10.0+1938+3b7755d4.3.x86_64.rpm
httpdx86_6465.module+el8.10.0+1984+1bed3124.4httpd-2.4.37-65.module+el8.10.0+1984+1bed3124.4.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
9 дней назад

ELSA-2026-42828: httpd:2.4 security, bug fix, and enhancement update (IMPORTANT)

rocky
9 дней назад

Important: httpd security, bug fix, and enhancement update

rocky
24 дня назад

Important: httpd security, bug fix, and enhancement update

oracle-oval
11 дней назад

ELSA-2026-41906: httpd security, bug fix, and enhancement update (IMPORTANT)

oracle-oval
15 дней назад

ELSA-2026-34109: httpd security, bug fix, and enhancement update (IMPORTANT)