Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:41906: Important: httpd security, bug fix, and enhancement update

This Red Hat Security Advisory addresses multiple Important-severity vulnerabilities in the Apache HTTP Server (httpd) for RHEL 9, including privilege escalation via .htaccess manipulation (CVE-2026-24072, CVSS 8.8), multiple denial-of-service vectors, and authentication bypasses. The update provides a security fix for CVE-2024-42516, an incomplete patch for CVE-2023-38709, and includes fixes for versions prior to Apache 2.4.67. Administrators should apply the provided Red Hat package updates to their affected RHEL 9 systems.
Read Full Article →

Red Hat Product Errata RHSA-2026:41906 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41906 - Security Advisory Overview Updated Packages Synopsis Important: httpd security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for httpd is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation (CVE-2026-24072) httpd: mod_auth_digest: timing attack allows a bypass of digest authentication (CVE-2026-33006) httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue (CVE-2026-42535) httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951) httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges (CVE-2026-44119) Bug Fix(es) and Enhancement(s): address Moderate severity issues from httpd 2.4.68 [rhel-9.8.z] (JIRA:RHEL-184520) mod_proxy_html regression in CVE-2026-34355 fix [rhel-9.8.z] (JIRA:RHEL-192752) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2374549 - CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709 BZ - 2464941 - CVE-2026-24072 Apache HTTP Server: mod_rewrite: Apache HTTP Server: Privilege Escalation via .htaccess file manipulation BZ - 2465293 - CVE-2026-33006 httpd: mod_auth_digest: timing attack allows a bypass of digest authentication BZ - 2465296 - CVE-2026-29169 httpd: NULL pointer dereference via specially crafted request BZ - 2486395 - CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers BZ - 2486397 - CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server BZ - 2486399 - CVE-2026-44631 httpd: Apache HTTP Server: Denial of Service via crafted regular expressions BZ - 2486402 - CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server BZ - 2486406 - CVE-2026-42535 httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue BZ - 2486411 - CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc BZ - 2486414 - CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass BZ - 2486415 - CVE-2026-43951 httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime BZ - 2486416 - CVE-2026-44119 httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges CVEs CVE-2024-42516 CVE-2026-24072 CVE-2026-29169 CVE-2026-33006 CVE-2026-34355 CVE-2026-34356 CVE-2026-42535 CVE-2026-42536 CVE-2026-43951 CVE-2026-44119 CVE-2026-44185 CVE-2026-44186 CVE-2026-44631 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM httpd-2.4.62-13.el9_8.5.src.rpm SHA-256: 6d76ac510d7cdbd615fafe6ba80afbc782488cf8c6d41c5698ff07e1800190b0 x86_64 httpd-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 5375adfa1a0a3675cf6bc7d9aa290ac133f52bf354dff8a75dd0af744212d38a httpd-core-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 32a3d89904bae9662b5cd8ed6d4896f9886ec7df7567f701e5a96fae5d7b7176 httpd-core-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 5058a16e54c2e25aa430d59ba267028a1705f351c45c19fcafbf00a8dd6a472e httpd-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 157d146f191a74fd29474c521ecc370005d07fe39119bc1a5e61d116f36a9f40 httpd-debugsource-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: ec6d0435896f163b53efbebd8ed534fdfe071cf33ffc1fc2b424f167cc44d5bc httpd-devel-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 490f175c4902b945e43b89170e28f13c52c36fe850ed686e0d49cf74967206ce httpd-filesystem-2.4.62-13.el9_8.5.noarch.rpm SHA-256: 029e57575e4e29e1a0f447084f5f65f5e62a2b6fa88aaf332c5159326cc691b1 httpd-manual-2.4.62-13.el9_8.5.noarch.rpm SHA-256: ac6cc04a19b6996d4ec3085f8b23481a80d355764dcd45876526c48b03bae062 httpd-tools-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 05417ee4fbfeb194b86be51b6498b6c433e497700b6bf9611b4f772618afc54b httpd-tools-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 947f5c8a67d1a97e96ddcb8d1def6571c9ab18c0172224479defb7806a337be2 mod_ldap-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 34d17610275017d1a70760cbe836f00f035d0899ac91baa8dffc3371242cd27d mod_ldap-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: f15877dbb380fd3fb77cb1f74030ff4ae2ee8f85afb6d53e20930112ee26efb0 mod_lua-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 4211aea26f82486e3f421b5401118827d8cd5528f5afb38a71a9d3e239b2a30b mod_lua-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 16f3a79456c1163934b882e10f04ed17ca4f0c5963c7b0ec3cd0bb68ce6a7a4d mod_proxy_html-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 36d27f197128ee1b2a3f8a2a333bed48af2effd850f070edee8477e7dd1f9a9d mod_proxy_html-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 7f8458d6b908fe5d21de346ccc9f6a56b338c79901b54f1b87f724fbd90cf29f mod_session-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 0741622a2737f48be9fbc2b3207cfd4d3fa1c8cbb07e3b56fbd8f4d37f7a69cf mod_session-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 3de0f3d2f01523a5613271c196c8e9f3f10417f04fe56346e2fd2b49c910f682 mod_ssl-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: bddd5ad09de29bf206dd8d4a860c175e04e47b1d5b52c8e898c2c2840c467747 mod_ssl-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 2c384048f7ffe147a2a12ee3fd8092d969843e129d2bc9a567bd5f2df328393c Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM httpd-2.4.62-13.el9_8.5.src.rpm SHA-256: 6d76ac510d7cdbd615fafe6ba80afbc782488cf8c6d41c5698ff07e1800190b0 x86_64 httpd-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 5375adfa1a0a3675cf6bc7d9aa290ac133f52bf354dff8a75dd0af744212d38a httpd-core-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 32a3d89904bae9662b5cd8ed6d4896f9886ec7df7567f701e5a96fae5d7b7176 httpd-core-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 5058a16e54c2e25aa430d59ba267028a1705f351c45c19fcafbf00a8dd6a472e httpd-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 157d146f191a74fd29474c521ecc370005d07fe39119bc1a5e61d116f36a9f40 httpd-debugsource-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: ec6d0435896f163b53efbebd8ed534fdfe071cf33ffc1fc2b424f167cc44d5bc httpd-devel-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 490f175c4902b945e43b89170e28f13c52c36fe850ed686e0d49cf74967206ce httpd-filesystem-2.4.62-13.el9_8.5.noarch.rpm SHA-256: 029e57575e4e29e1a0f447084f5f65f5e62a2b6fa88aaf332c5159326cc691b1 httpd-manual-2.4.62-13.el9_8.5.noarch.rpm SHA-256: ac6cc04a19b6996d4ec3085f8b23481a80d355764dcd45876526c48b03bae062 httpd-tools-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 05417ee4fbfeb194b86be51b6498b6c433e497700b6bf9611b4f772618afc54b httpd-tools-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 947f5c8a67d1a97e96ddcb8d1def6571c9ab18c0172224479defb7806a337be2 mod_ldap-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 34d17610275017d1a70760cbe836f00f035d0899ac91baa8dffc3371242cd27d mod_ldap-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: f15877dbb380fd3fb77cb1f74030ff4ae2ee8f85afb6d53e20930112ee26efb0 mod_lua-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 4211aea26f82486e3f421b5401118827d8cd5528f5afb38a71a9d3e239b2a30b mod_lua-debuginfo-2.4.62-13.el9_8.5.x86_64.rpm SHA-256: 16f3a79456c1163934b882e10f04ed17ca4f

Share this article