[security - high] httpd:2.4 security, bug fix, and enhancement update
エラータID: AXSA:2026-1408:01
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.
Security Fix(es):
* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
* httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
* httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
Bug Fix(es) and Enhancement(s):
* mod_proxy_html regression in CVE-2026-34355 fix [rhel-8.10.z] (JIRA:RHEL-192751)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2023-38709
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
CVE-2024-42516
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
CVE-2026-29169
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
CVE-2026-34355
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-34356
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-42536
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-43951
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
CVE-2026-44185
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44186
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44631
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Modularity name: "httpd"
Stream name: "2.4"
Update packages.
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
N/A
SRPMS
- httpd-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.src.rpm
MD5: 0bd1729f32de853848f046eca2c76449
SHA-256: af4a9d618dfe5d624daef044e000672c1390d4d800f86c96e828afa822527504
Size: 7.01 MB - mod_http2-1.15.7-10.module+el8+2017+d2a8b6e2.7.src.rpm
MD5: eb5b09972d8aad713a84b6675378024d
SHA-256: 4bedcd467fb15043de31113e8b335a366572c20b7d3097b8ec2a2c6457442cf8
Size: 1.03 MB - mod_md-2.0.8-8.module+el8+2017+d2a8b6e2.2.src.rpm
MD5: 0e988ba0b88c59fa8522c64b1e019166
SHA-256: 3d07c07015621f5e296e6c06afb9219de43faa3cb1305d0f9ad0c74c1cb561f4
Size: 636.07 kB
Asianux Server 8 for x86_64
- httpd-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 43188ce20115bd6ab0744f7db89a7d77
SHA-256: 59e3c66bbaefc935eac988dd432712d872ba11bcf0e24f092bda84d23d2bc8f2
Size: 1.42 MB - httpd-debugsource-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 2c25925e8b1da3f66bdc461d4b20b54b
SHA-256: 08fd1ad9b4620c218ca67cb91c2beac6ec50efef4730b0fb802a25f1769ef085
Size: 1.46 MB - httpd-devel-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 419a741c65d3f53aa58f62fe78cb1435
SHA-256: 05b1b57d4d4239d0fc177fab8ed25b3162bf558d918360d3bb6e0de0482068a8
Size: 231.33 kB - httpd-filesystem-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.noarch.rpm
MD5: 67d053b587ff6bd0a606ebaddaa4b3b1
SHA-256: c91bac6631e3d4ba8d64fe3f96d5cbf3daf567e777bae2f090c81a3433ce4062
Size: 47.46 kB - httpd-manual-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.noarch.rpm
MD5: c97f1db0a10e487addf225f836c28fa6
SHA-256: cac10722e1da63153695deafdf4d1f4695c65a0086c614c7724e55138079f00e
Size: 2.38 MB - httpd-tools-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 4214e39341574fe4bc46aee0fb6d4df0
SHA-256: c5877480961d933fffe4a11d368c7b9b00ae03347d5da6c37120916016c71328
Size: 114.54 kB - mod_http2-1.15.7-10.module+el8+2017+d2a8b6e2.7.x86_64.rpm
MD5: 631eb5e69ab7bbaa68889a10e653c4fa
SHA-256: ac27591286e081c7504a38acd65fe592ae5a4df5be92ea7e9437037965c1670b
Size: 155.92 kB - mod_http2-debugsource-1.15.7-10.module+el8+2017+d2a8b6e2.7.x86_64.rpm
MD5: 1030e355750817491d00ee18a48a82b4
SHA-256: 48e9067bd97d6ea783070a6f731544410b5cfcc7c9daaac8808bc08081e64acf
Size: 149.92 kB - mod_ldap-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: df0e28a20d09ff0224bcbdd8f8a52021
SHA-256: 9f83f16f3c78c9c8b4f598f28c49e7cf0d313c29ee654efe829c63d8343882a2
Size: 92.77 kB - mod_md-2.0.8-8.module+el8+2017+d2a8b6e2.2.x86_64.rpm
MD5: 770b0194e0137c6db4064648fea751dd
SHA-256: 965fddc064a92a68bef168bdb2259d814aa7f7dc2969731d49f11aa6156e327e
Size: 183.56 kB - mod_md-debugsource-2.0.8-8.module+el8+2017+d2a8b6e2.2.x86_64.rpm
MD5: 2b58a5666634d8ada1356e34e46b2c59
SHA-256: 03029050b12ca6932a7426ab74069202b550abdc075326b957bf59586247ddb5
Size: 126.48 kB - mod_proxy_html-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 691b9c5c4d46c887ed2428f219b4e753
SHA-256: b2fb7d3a09e83f6607259adeb0fe35f78f4e01a46a66df4a4a85f98fcb084f20
Size: 69.70 kB - mod_session-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 42c6bc53f2855e4d82def4abe5d654e5
SHA-256: e7c7670a01ddebdacc4d9c9d61a18e8a0ad146c6394483a104b33855162c6707
Size: 81.56 kB - mod_ssl-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
MD5: 0906c6ccb01df5e1e75e38b1b8c1cdf9
SHA-256: 8fce7b63b37a769b48f24df52d67d6166504c25ae6ae9543ba7586383ca05d7d
Size: 144.92 kB