Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:64794

Опубликовано: 08 сент. 2026
Источник: rocky
Оценка: Low

Описание

Low: httpd:2.4 security update

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

  • httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
httpdaarch6465.module+el8.10.0+1938+3b7755d4.3httpd-2.4.37-65.module+el8.10.0+1938+3b7755d4.3.aarch64.rpm
httpdaarch6465.module+el8.10.0+40053+5a18018e.7httpd-2.4.37-65.module+el8.10.0+40053+5a18018e.7.aarch64.rpm
httpdaarch6465.module+el8.10.0+1842+4a9649e8.2httpd-2.4.37-65.module+el8.10.0+1842+4a9649e8.2.aarch64.rpm
httpdaarch6465.module+el8.10.0+40257+286895ef.9httpd-2.4.37-65.module+el8.10.0+40257+286895ef.9.aarch64.rpm
httpdaarch6465.module+el8.10.0+2061+8d03fdec.5httpd-2.4.37-65.module+el8.10.0+2061+8d03fdec.5.aarch64.rpm
httpdaarch6465.module+el8.10.0+1830+22f0c9e0httpd-2.4.37-65.module+el8.10.0+1830+22f0c9e0.aarch64.rpm
httpdaarch6465.module+el8.10.0+1984+1bed3124.4httpd-2.4.37-65.module+el8.10.0+1984+1bed3124.4.aarch64.rpm
httpdaarch6465.module+el8.10.0+40197+0231e209.8httpd-2.4.37-65.module+el8.10.0+40197+0231e209.8.aarch64.rpm
httpdaarch6465.module+el8.10.0+40206+be2c8a50.8httpd-2.4.37-65.module+el8.10.0+40206+be2c8a50.8.aarch64.rpm
httpdaarch6465.module+el8.10.0+1840+b070a976.1httpd-2.4.37-65.module+el8.10.0+1840+b070a976.1.aarch64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 9.8
ubuntu
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 4.6
redhat
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

CVSS3: 9.8
nvd
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

msrc
3 месяца назад

Apache HTTP Server: mod_ldap per-dir use-after-free

CVSS3: 9.8
debian
3 месяца назад

Use After Free vulnerability in Apache HTTP Server with mod_ldap in pe ...