[security - high] httpd:2.4 security, bug fix, and enhancement update

エラータID: AXSA:2026-1408:01

Release date: 
Friday, July 31, 2026 - 21:18
Subject: 
[security - high] httpd:2.4 security, bug fix, and enhancement update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
* httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
* httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)

Bug Fix(es) and Enhancement(s):

* mod_proxy_html regression in CVE-2026-34355 fix [rhel-8.10.z] (JIRA:RHEL-192751)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-38709
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
CVE-2024-42516
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
CVE-2026-29169
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
CVE-2026-34355
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-34356
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-42536
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-43951
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
CVE-2026-44185
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44186
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44631
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Modularity name: "httpd"
Stream name: "2.4"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. httpd-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.src.rpm
    MD5: 0bd1729f32de853848f046eca2c76449
    SHA-256: af4a9d618dfe5d624daef044e000672c1390d4d800f86c96e828afa822527504
    Size: 7.01 MB
  2. mod_http2-1.15.7-10.module+el8+2017+d2a8b6e2.7.src.rpm
    MD5: eb5b09972d8aad713a84b6675378024d
    SHA-256: 4bedcd467fb15043de31113e8b335a366572c20b7d3097b8ec2a2c6457442cf8
    Size: 1.03 MB
  3. mod_md-2.0.8-8.module+el8+2017+d2a8b6e2.2.src.rpm
    MD5: 0e988ba0b88c59fa8522c64b1e019166
    SHA-256: 3d07c07015621f5e296e6c06afb9219de43faa3cb1305d0f9ad0c74c1cb561f4
    Size: 636.07 kB

Asianux Server 8 for x86_64
  1. httpd-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 43188ce20115bd6ab0744f7db89a7d77
    SHA-256: 59e3c66bbaefc935eac988dd432712d872ba11bcf0e24f092bda84d23d2bc8f2
    Size: 1.42 MB
  2. httpd-debugsource-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 2c25925e8b1da3f66bdc461d4b20b54b
    SHA-256: 08fd1ad9b4620c218ca67cb91c2beac6ec50efef4730b0fb802a25f1769ef085
    Size: 1.46 MB
  3. httpd-devel-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 419a741c65d3f53aa58f62fe78cb1435
    SHA-256: 05b1b57d4d4239d0fc177fab8ed25b3162bf558d918360d3bb6e0de0482068a8
    Size: 231.33 kB
  4. httpd-filesystem-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.noarch.rpm
    MD5: 67d053b587ff6bd0a606ebaddaa4b3b1
    SHA-256: c91bac6631e3d4ba8d64fe3f96d5cbf3daf567e777bae2f090c81a3433ce4062
    Size: 47.46 kB
  5. httpd-manual-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.noarch.rpm
    MD5: c97f1db0a10e487addf225f836c28fa6
    SHA-256: cac10722e1da63153695deafdf4d1f4695c65a0086c614c7724e55138079f00e
    Size: 2.38 MB
  6. httpd-tools-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 4214e39341574fe4bc46aee0fb6d4df0
    SHA-256: c5877480961d933fffe4a11d368c7b9b00ae03347d5da6c37120916016c71328
    Size: 114.54 kB
  7. mod_http2-1.15.7-10.module+el8+2017+d2a8b6e2.7.x86_64.rpm
    MD5: 631eb5e69ab7bbaa68889a10e653c4fa
    SHA-256: ac27591286e081c7504a38acd65fe592ae5a4df5be92ea7e9437037965c1670b
    Size: 155.92 kB
  8. mod_http2-debugsource-1.15.7-10.module+el8+2017+d2a8b6e2.7.x86_64.rpm
    MD5: 1030e355750817491d00ee18a48a82b4
    SHA-256: 48e9067bd97d6ea783070a6f731544410b5cfcc7c9daaac8808bc08081e64acf
    Size: 149.92 kB
  9. mod_ldap-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: df0e28a20d09ff0224bcbdd8f8a52021
    SHA-256: 9f83f16f3c78c9c8b4f598f28c49e7cf0d313c29ee654efe829c63d8343882a2
    Size: 92.77 kB
  10. mod_md-2.0.8-8.module+el8+2017+d2a8b6e2.2.x86_64.rpm
    MD5: 770b0194e0137c6db4064648fea751dd
    SHA-256: 965fddc064a92a68bef168bdb2259d814aa7f7dc2969731d49f11aa6156e327e
    Size: 183.56 kB
  11. mod_md-debugsource-2.0.8-8.module+el8+2017+d2a8b6e2.2.x86_64.rpm
    MD5: 2b58a5666634d8ada1356e34e46b2c59
    SHA-256: 03029050b12ca6932a7426ab74069202b550abdc075326b957bf59586247ddb5
    Size: 126.48 kB
  12. mod_proxy_html-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 691b9c5c4d46c887ed2428f219b4e753
    SHA-256: b2fb7d3a09e83f6607259adeb0fe35f78f4e01a46a66df4a4a85f98fcb084f20
    Size: 69.70 kB
  13. mod_session-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 42c6bc53f2855e4d82def4abe5d654e5
    SHA-256: e7c7670a01ddebdacc4d9c9d61a18e8a0ad146c6394483a104b33855162c6707
    Size: 81.56 kB
  14. mod_ssl-2.4.37-65.module+el8+2017+d2a8b6e2.9.ML.1.x86_64.rpm
    MD5: 0906c6ccb01df5e1e75e38b1b8c1cdf9
    SHA-256: 8fce7b63b37a769b48f24df52d67d6166504c25ae6ae9543ba7586383ca05d7d
    Size: 144.92 kB