apr-util-1.6.1-23.el9_8.1

エラータID: AXSA:2026-1836:01

Release date: 
Tuesday, September 15, 2026 - 18:58
Subject: 
apr-util-1.6.1-23.el9_8.1
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The mission of the Apache Portable Runtime (APR) is to provide a free library of C data structures and routines. This library contains additional utility interfaces for APR; including support for XML, LDAP, database interfaces, URI parsing and more.

Security Fix(es):

* apr-util: Apache Portable Runtime Utility: Heap buffer overflow in redis client (CVE-2026-34501)
* apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation (CVE-2025-49506)
* apr-util: Apache Portable Runtime Utility: Denial of Service via XML stack recursion attack (CVE-2026-32327)
* apr-util: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client (CVE-2026-34502)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34501
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-34502
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. apr-util-1.6.1-23.el9_8.1.src.rpm
    MD5: 3bf51398c1ea8a192b00c78dd5741835
    SHA-256: 87c2bd48cab7661eb22fa221a60cf100a2195c76df2c1abef686e97ea7f7964d
    Size: 446.82 kB

Asianux Server 9 for x86_64
  1. apr-util-1.6.1-23.el9_8.1.i686.rpm
    MD5: 362f767ac4f49168825b86501339eb45
    SHA-256: 1aedd10a122abce8805314603e82af38682ae818243ae29fbb5a596eb2fa6069
    Size: 103.44 kB
  2. apr-util-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: e1ef7edf24ecc6b2ce0ef2c38d9c4767
    SHA-256: 8b12d2ce8ed46633e9e254932601159cb1eea6e09a419edaa66b20555693f19d
    Size: 94.39 kB
  3. apr-util-bdb-1.6.1-23.el9_8.1.i686.rpm
    MD5: 5dfcd5d700f1ab2c11340eae9b78ee13
    SHA-256: 3192d5c76d8fc7699584fccb8d88d0bf863c2e5a8df82896368ea82415de20a2
    Size: 12.11 kB
  4. apr-util-bdb-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 8e05a2f6e9ad60d892d4c575b549344f
    SHA-256: fa38ab8e47debc2d1c95388026e99b519279849de01640f571ca60e4ea7c7ac7
    Size: 11.89 kB
  5. apr-util-devel-1.6.1-23.el9_8.1.i686.rpm
    MD5: ca46d5dcbffe21cf6d583322077e0140
    SHA-256: 62563a5d96138088c2f950cd2c0d9f09422b9a9449512b334ad417ad38ca792b
    Size: 79.38 kB
  6. apr-util-devel-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: eaa20671563d7d3d0d143d9c583556a1
    SHA-256: 2857feb2b576cbe8e86dce863ae0408fdb5a3379e8a8cffa65ab70890755fff7
    Size: 79.34 kB
  7. apr-util-ldap-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 36c5b5fef5128a132af48f1de77d0234
    SHA-256: 21cceab1b099778dcc6282bff7ace52102779b5da655eda3c5b65fb96872f28c
    Size: 12.92 kB
  8. apr-util-mysql-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 890b9939fc13bac0c0f31cee67b20a64
    SHA-256: 77d30be550204a316d729d63d225535cdcb28b43c83c0687674fbe4d314a1101
    Size: 17.41 kB
  9. apr-util-odbc-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 5973cc8ae9f86d92dd0a92e613f20513
    SHA-256: 54fefa6c0b20f673f4664caa0f32be331e51caf6aefd2aea2518755ce97d343d
    Size: 21.24 kB
  10. apr-util-openssl-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 1e081d843404c71f768e94f81add0e66
    SHA-256: 4297283ed17a6915a812f8842ec8757147e5b6d1a5e2f980532748c52d5aa480
    Size: 14.37 kB
  11. apr-util-pgsql-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 4538ba2b7382fd5c696b9e56e67dd482
    SHA-256: a974f40b73d2327a6d7d32caac8feb149e85222943dd62fcff715b7c3c91ca52
    Size: 17.01 kB
  12. apr-util-sqlite-1.6.1-23.el9_8.1.x86_64.rpm
    MD5: 472d0aab38ae8da05abf50c9b09e7aee
    SHA-256: 0b6f25a421aa019d3e18d745f971314800d6a9366e216aeb0ec0643f4ba16f79
    Size: 15.12 kB