Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:42828: Important: httpd:2.4 security, bug fix, and enhancement update

This Red Hat Security Advisory addresses multiple vulnerabilities in the Apache HTTP Server (httpd:2.4 module), including heap-based buffer overflows, denial-of-service conditions, and security bypasses via crafted requests or malicious backend servers. The CVSS base scores for the listed CVEs are rated as Important, with specific scores like 7.5 (HIGH) for CVE-2024-42516 and CVE-2026-29169. Affected versions are Apache HTTP Server 2.4.0 through 2.4.63 for CVE-2024-42516 and versions prior to 2.4.67 for CVE-2026-29169, requiring an update to the patched httpd packages provided by Red Hat.
Read Full Article →

Red Hat Product Errata RHSA-2026:42828 - Security Advisory Issued: 2026-07-21 Updated: 2026-07-21 RHSA-2026:42828 - Security Advisory Overview Updated Packages Synopsis Important: httpd:2.4 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the httpd:2.4 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951) Bug Fix(es) and Enhancement(s): mod_proxy_html regression in CVE-2026-34355 fix [rhel-8.10.z] (JIRA:RHEL-192751) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2374549 - CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709 BZ - 2465296 - CVE-2026-29169 httpd: NULL pointer dereference via specially crafted request BZ - 2486395 - CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers BZ - 2486397 - CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server BZ - 2486399 - CVE-2026-44631 httpd: Apache HTTP Server: Denial of Service via crafted regular expressions BZ - 2486402 - CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server BZ - 2486411 - CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc BZ - 2486414 - CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass BZ - 2486415 - CVE-2026-43951 httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVEs CVE-2024-42516 CVE-2026-29169 CVE-2026-34355 CVE-2026-34356 CVE-2026-42536 CVE-2026-43951 CVE-2026-44185 CVE-2026-44186 CVE-2026-44631 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM httpd-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.src.rpm SHA-256: 7563988414aef311fbeba4eca7baaff6210b586f166e357dc85cd3ffd040433c mod_http2-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.src.rpm SHA-256: 9113f414dd0ec48a5f00f04a04b30b9627396800915bbe0aa606f6f244e0a5df mod_md-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.src.rpm SHA-256: 79fc3c0d9aaf015a3e1b7afd26e475420f685b3aed9827368b6094b3dcaf80e0 x86_64 httpd-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 2b4f6782f6471970d4483fe25a7fce01a6827db3c075038813a454ae8e549a7f httpd-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 184d4f87b0cb1a31fc5f57b8ceb9503a367c5342de19c3b809ded6225c57e1e7 httpd-debugsource-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: c4f521defcee3155f315b887e24a259751384db75ff9bf516fb75ebc092fbf3a httpd-devel-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 2596ad17d562d07a68f42b9c3d779799d038bf85367ab6f72b15bafd2e9d9c1d httpd-tools-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 57fb569d157fbaa31a38dc9abcf98bff8416d230c57ab4f564a1190fc248d668 httpd-tools-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 7e9a23ee5191142e0091b48c068dde597083eeae0fabcc138c54e6faef3451f1 mod_http2-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.x86_64.rpm SHA-256: 4c6897d05f6ac81187507ef21c87490a313b29b70f0098c2f7f866bf9f53d9b4 mod_http2-debuginfo-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.x86_64.rpm SHA-256: 5f02c4b279b285a646ffe6f16114d9196a737a1b0c2d409156403b5639c87b89 mod_http2-debugsource-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.x86_64.rpm SHA-256: 4b34c6b2fbe572d4e48b618be1353fb9d38035ffd97904ec4429bdf2d16b3ddb mod_ldap-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: e63552fe9958e14a55af4f31b3b98c527d774d23f1528d8f92efd0295e2703a5 mod_ldap-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: a5dc072cabf09b655d29e826ff9b775fb22926d9e1302ed572dded51f3ee3a87 mod_md-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.x86_64.rpm SHA-256: ff96565db59c708b0bb84d600b8ee01eec951e0320937e15782f38a4fb853749 mod_md-debuginfo-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.x86_64.rpm SHA-256: a5875ad00ed2b1e796cd0dc4292b05ebe73dbcb71b33f85a35c407b7d3db20a4 mod_md-debugsource-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.x86_64.rpm SHA-256: 5c9bd8863303a23ddc952fdd285c3d4cc5cdce4ddf334e3ede03456a00615c1b mod_proxy_html-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: f18c4c12783fe68d015b60562a31cd14fe08f4702985df57ba71df07bc06f6d1 mod_proxy_html-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: a71393658316e29988336a5c6138bc2e1f0f2a366379be0daff68f40d0f8eeb3 mod_session-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 44b1c99bfae555651d8f15d9e6097b7698e7af71e95d0e303e4c12052ddb6090 mod_session-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 48acef51c7ae80596cbd3a17f5bff33b39f43b349ee34033c3879e35c8b351c9 mod_ssl-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: b971f0efa92fe70b0c4b7a22a0103eb7d9e9286adc1a61390b5a6c8a84c16d76 mod_ssl-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.x86_64.rpm SHA-256: 83cec164c1d2440f277aa523f5167b25636280602d1b931f7928b4a6a9feee99 Red Hat Enterprise Linux for IBM z Systems 8 SRPM httpd-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.src.rpm SHA-256: 7563988414aef311fbeba4eca7baaff6210b586f166e357dc85cd3ffd040433c mod_http2-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.src.rpm SHA-256: 9113f414dd0ec48a5f00f04a04b30b9627396800915bbe0aa606f6f244e0a5df mod_md-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.src.rpm SHA-256: 79fc3c0d9aaf015a3e1b7afd26e475420f685b3aed9827368b6094b3dcaf80e0 s390x httpd-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: 521292d2c01ef1e3546b965507d8cb89f20acd088f311376a59364a885d78403 httpd-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: b8bfacd138bd6a937be4ab4712b5674c0b2824dd0fb1c3f226b34bae81589d42 httpd-debugsource-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: e05e35e269460aa4e6dd3f620664e1b058d8b5b50d5fe1e6ee7192714a9e1cb7 httpd-devel-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: c9924996d50b2b1c6efe24327d549b3f87e9cdfdd4e10aeb69b166bb59b081b2 httpd-tools-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: 222b4a1a0975fd07226e2f700246223253ecd05706277283a2b6a5d836e0bba5 httpd-tools-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: 4b60e410ef8b08eccef007852ebe097090965639dd922dbab16a717c54f43b83 mod_http2-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.s390x.rpm SHA-256: 466b0585195d69c2155e5bd95ee40650c91255cec75a821c4b165dce9bb04ae1 mod_http2-debuginfo-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.s390x.rpm SHA-256: edb9f4eb0e1700c0b3f5f7a212334e576c6f5743245da9a82dbdca32ebc80b11 mod_http2-debugsource-1.15.7-10.module+el8.10.0+24521+219dcfc5.7.s390x.rpm SHA-256: fdec5117b7d0643ec2b86c85bd1c09a8543fa7c0a6b02af277406ef915f078fd mod_ldap-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: 75ab7b32f18b6e17e95e762adc4cdbe5337e238f04011094ab7085bf8d084347 mod_ldap-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: fed1acbacf9dd455d1da3e75a508e71321f38ac3451ff24f3bc599541da0e021 mod_md-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.s390x.rpm SHA-256: 224b7dad70c5755b1ef890c322cf22c4158a41133d0ab37e06a1d752abd21911 mod_md-debuginfo-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.s390x.rpm SHA-256: 85e5441b14b33ce053a21c22adf191f133a13b63036c3cc69077f7b87fd9c20b mod_md-debugsource-2.0.8-8.module+el8.10.0+23815+1b5e1c66.2.s390x.rpm SHA-256: f74e2a9f14ae78dfdd9a8cc0123b94236a12fe14efea938773bdb92a1207acf8 mod_proxy_html-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-256: abd34513b52654ffaf3daa888b8f1397f24ce445f1c4a6b8c371783834cbe072 mod_proxy_html-debuginfo-2.4.37-65.module+el8.10.0+24521+219dcfc5.9.s390x.rpm SHA-2

Share this article