apr-util-1.6.1-9.el8_10.1
エラータID: AXSA:2026-1895:02
The mission of the Apache Portable Runtime (APR) is to provide a free library of C data structures and routines. This library contains additional utility interfaces for APR; including support for XML, LDAP, database interfaces, URI parsing and more.
Security Fix(es):
* apr-util: Apache Portable Runtime Utility: Heap buffer overflow in redis client (CVE-2026-34501)
* apr-util: Apache Portable Runtime Utility: Information disclosure via timing attack in password validation (CVE-2025-49506)
* apr-util: Apache Portable Runtime Utility: Denial of Service via XML stack recursion attack (CVE-2026-32327)
* apr-util: Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client (CVE-2026-34502)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2025-49506
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34501
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
CVE-2026-34502
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
Update packages.
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
N/A
SRPMS
- apr-util-1.6.1-9.el8_10.1.src.rpm
MD5: c9a13c1639e38fd0c6cfa8ebdbcd9611
SHA-256: 63ad043d6c1fe0241c7c20ec00757d4d3d89d6fbc1c111c592d05492d6dffb5a
Size: 458.03 kB
Asianux Server 8 for x86_64
- apr-util-1.6.1-9.el8_10.1.i686.rpm
MD5: 5ae8e6cfcc4a22fe8c2c1726a65b0e13
SHA-256: 846f80befb2a12c4ba8c2aad32177fa0d382175b94097d6d513fcb57dfe10e2c
Size: 114.06 kB - apr-util-1.6.1-9.el8_10.1.x86_64.rpm
MD5: a6b90f085a9515545b44ff2014c2c527
SHA-256: 826d57195b51c307c759fbeb5bf6c54e84552c73c6f99804cc5f7cd6b8a60953
Size: 105.64 kB - apr-util-bdb-1.6.1-9.el8_10.1.i686.rpm
MD5: f679be41b8b6a4e1f12622bd231e46b4
SHA-256: 4c70183ec759e259cb365c6400e8875b5d2c516d193f5f779e94e7e7d876550f
Size: 24.73 kB - apr-util-bdb-1.6.1-9.el8_10.1.x86_64.rpm
MD5: ed1656ece7e55cbe221f219480e5ab37
SHA-256: 61ae3145c1f944c48afd801084464d895303f88bd7d0e9a5c208c87086f4c160
Size: 24.30 kB - apr-util-devel-1.6.1-9.el8_10.1.i686.rpm
MD5: cc52147a4e40eeac82d06c35f0b01421
SHA-256: cb8585b05e3b1769134fd2acf8e3dabd22ac09fbc85295f587a26d5f49e365f5
Size: 85.75 kB - apr-util-devel-1.6.1-9.el8_10.1.x86_64.rpm
MD5: 63923333b80610b32c7f5ed686658f58
SHA-256: 73db891ba3a7daf684c8b15d207dd244033ad6c7824f53bf5dc99f7319b31a1a
Size: 85.72 kB - apr-util-ldap-1.6.1-9.el8_10.1.x86_64.rpm
MD5: a3a84761b33c12c45857b02387278625
SHA-256: 913d5268cd1677d355410e27ed29494d320fdb1d2d3688f23ff7a5fae7086c12
Size: 25.21 kB - apr-util-mysql-1.6.1-9.el8_10.1.x86_64.rpm
MD5: 35e4e622f181035f19f0d159b2317681
SHA-256: 0f130d4eda5a21f194a0cf1513b5f7380fb075fd689b7f710f0ad221189acd5c
Size: 29.56 kB - apr-util-odbc-1.6.1-9.el8_10.1.x86_64.rpm
MD5: 7f949e7b1ecdb784e8547039648f55d6
SHA-256: 10cf907402236e0a4e96f3d1549773abd6928fe73123f4724437a9baa0a2c727
Size: 33.14 kB - apr-util-openssl-1.6.1-9.el8_10.1.i686.rpm
MD5: 47ecf15c081c68e916d6a1a55a52ed6a
SHA-256: 354abc40a186209e2b38bed2c131b37515cbe76d971fd973322e96162f7f2fa8
Size: 26.80 kB - apr-util-openssl-1.6.1-9.el8_10.1.x86_64.rpm
MD5: 067cbe063ba8c9eb7eb360023cc8e6db
SHA-256: 1e7d3fd403371992250890931f678eadf095727273e134deeadb1656484ede66
Size: 26.51 kB - apr-util-pgsql-1.6.1-9.el8_10.1.x86_64.rpm
MD5: 00d6693693d42bd0e04ac77bbe4e806d
SHA-256: 29ae2a21babdab381a742e501c5af12ff747fa4f5b269d5cbdc67064d3d193ea
Size: 29.48 kB - apr-util-sqlite-1.6.1-9.el8_10.1.x86_64.rpm
MD5: c2013d11788296884e0b7e31d2033bf7
SHA-256: f2314e7acb577c4b907afded443fff0444d132c3e3a31646ffe0703091450b81
Size: 27.34 kB