httpd-2.4.62-13.el9_8.5

エラータID: AXSA:2026-1520:08

Release date: 
Thursday, August 13, 2026 - 15:42
Subject: 
httpd-2.4.62-13.el9_8.5
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072)
* httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
* httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
* httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
* httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)
* httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119)

Bug Fix(es) and Enhancement(s):

* address Moderate severity issues from httpd 2.4.68 [rhel-9.8.z] (JIRA:RHEL-184520)
* mod_proxy_html regression in CVE-2026-34355 fix [rhel-9.8.z] (JIRA:RHEL-192752)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2023-38709
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
CVE-2024-42516
HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 but the patch included in Apache HTTP Server 2.4.59 did not address the issue. Users are recommended to upgrade to version 2.4.64, which fixes this issue.
CVE-2026-24072
An escalation of privilege bug in various modules in Apache HTTP 2.4.66 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
CVE-2026-29169
A NULL pointer dereference in mod_dav_lock in Apache HTTP Server 2.4.66 and earlier may allow an attacker to crash the server with a malicious request.mod_dav_lock is not used internally by mod_dav or mod_dav_fs. The only known use-case for mod_dav_lock was mod_dav_svn from Apache Subversion earlier than version 1.2.0. Users are recommended to upgrade to version 2.4.66, which fixes this issue, or remove mod_dav_lock.
CVE-2026-33006
A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remote attacker. Users are recommended to upgrade to version 2.4.67, which fixes this issue.
CVE-2026-34355
A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-34356
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-42535
A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes this issue.
CVE-2026-42536
Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-43951
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
CVE-2026-44119
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44185
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44186
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue affects undefined: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.
CVE-2026-44631
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. httpd-2.4.62-13.el9_8.5.src.rpm
    MD5: ab16895eb908e466b6d104a394edf1a1
    SHA-256: 299bb1ff61e6442099b9f15d05922730ab8faec446cb8fce854a08c02d9e7a17
    Size: 7.68 MB

Asianux Server 9 for x86_64
  1. httpd-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: de8c390cea1fd599667ffbc7a13c1c74
    SHA-256: 9f185a269a579ae00b6e94a75c14d80c58d1fff0cce32b7ba66cbd7c08b2f21f
    Size: 51.39 kB
  2. httpd-core-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: 1a7da4fd0a6c67f5027f08f9a12283df
    SHA-256: e71bfe91569e765290843d4c5a4d891aab52d07f11f9098ab2cf62723443bbf1
    Size: 1.47 MB
  3. httpd-devel-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: a56b5f836f52c3842561e653cb555d46
    SHA-256: cf01b67ce3105af27847ff9f67b722c656e7cd1616551fe63f302a4a69f5d6f4
    Size: 212.32 kB
  4. httpd-filesystem-2.4.62-13.el9_8.5.noarch.rpm
    MD5: dd496cd60daef9ca0779406c7d1635aa
    SHA-256: d9698a7f63224d3593617caa3528be0a8a90df79e64f3cac4f373e481cac04b4
    Size: 13.12 kB
  5. httpd-manual-2.4.62-13.el9_8.5.noarch.rpm
    MD5: ed74a7b21eb4dd774ca6d1a732c4594d
    SHA-256: 7dcdf55c0f825d128e1790c8e8d480ceb1533f91a804099e03be0ce057b5f392
    Size: 2.30 MB
  6. httpd-tools-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: 22aee0ab8e22b4fa04a428550b01a29e
    SHA-256: 4f7fc19aee107f4aef17f4c3f53a4c5cad8610278392fdebf149095604745e2e
    Size: 83.88 kB
  7. mod_ldap-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: cb8c47b021a6086485fa02f102f645f8
    SHA-256: 83e869ec7f6554a57195917c0ca30258604f1cb3607e3a9e43a279fb135c0cd0
    Size: 60.59 kB
  8. mod_lua-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: f8e2108bfd07e3573b0ce0fdf9ce1c8e
    SHA-256: 8f2847cc392b3886e3f41a5417a529be3b4b5bb5de994c08dbdbe15b396affe1
    Size: 59.79 kB
  9. mod_proxy_html-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: c86fb5e3e60d66a28fb4b94e2b0a81f6
    SHA-256: 6012592bfb5a1a82c9079e4da4fc750a36529e9904e1910120788148e7e4dbe6
    Size: 35.17 kB
  10. mod_session-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: 7b446b652794fe0839bdf4e482b27143
    SHA-256: 2b6fc8c11cb1d1b46438d51c609483ec61e9c21e06c29328975aa39a9a56ac19
    Size: 47.22 kB
  11. mod_ssl-2.4.62-13.el9_8.5.x86_64.rpm
    MD5: 70ef0cca86da0e3d416f3f936497595c
    SHA-256: 4e9526085a987b58fb430398100bcf12ff42718f77816d64f9272558fc2dac1d
    Size: 111.56 kB