Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:60004

Опубликовано: 26 авг. 2026
Источник: rocky
Оценка: Low

Описание

Low: httpd security update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
httpd-filesystemnoarch13.el10_2.6httpd-filesystem-2.4.63-13.el10_2.6.noarch.rpm
mod_sslaarch6413.el10_2.6mod_ssl-2.4.63-13.el10_2.6.aarch64.rpm
mod_luaaarch6413.el10_2.6mod_lua-2.4.63-13.el10_2.6.aarch64.rpm
httpd-develaarch6413.el10_2.6httpd-devel-2.4.63-13.el10_2.6.aarch64.rpm
httpd-toolsaarch6413.el10_2.6httpd-tools-2.4.63-13.el10_2.6.aarch64.rpm
httpdaarch6413.el10_2.6httpd-2.4.63-13.el10_2.6.aarch64.rpm
mod_proxy_htmlaarch6413.el10_2.6mod_proxy_html-2.4.63-13.el10_2.6.aarch64.rpm
mod_sessionaarch6413.el10_2.6mod_session-2.4.63-13.el10_2.6.aarch64.rpm
httpd-coreaarch6413.el10_2.6httpd-core-2.4.63-13.el10_2.6.aarch64.rpm
mod_ldapaarch6413.el10_2.6mod_ldap-2.4.63-13.el10_2.6.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 4.6
redhat
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 9.8
nvd
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
3 месяца назад

Apache HTTP Server: mod_ldap per-dir use-after-free

CVSS3: 9.8
debian
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in pe ...