Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:62165: Important: httpd security update

  • What: httpd security update
  • Impact: Red Hat Enterprise Linux 9.6 users need to apply patch
Read Full Article →

Red Hat Product Errata RHSA-2026:62165 - Security Advisory Issued: 2026-09-01 Updated: 2026-09-01 RHSA-2026:62165 - Security Advisory Overview Updated Packages Synopsis Important: httpd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for httpd is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059) httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash (CVE-2026-33007) Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167) httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2374549 - CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709 BZ - 2464940 - CVE-2026-34059 httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() BZ - 2464952 - CVE-2026-34032 httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check BZ - 2464953 - CVE-2026-33857 httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions BZ - 2465296 - CVE-2026-29169 httpd: NULL pointer dereference via specially crafted request BZ - 2465299 - CVE-2026-33007 httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash BZ - 2466913 - CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow BZ - 2486394 - CVE-2026-29167 httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration BZ - 2486395 - CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers BZ - 2486397 - CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server BZ - 2486399 - CVE-2026-44631 httpd: Apache HTTP Server: Denial of Service via crafted regular expressions BZ - 2486402 - CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server BZ - 2486411 - CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc BZ - 2486414 - CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass BZ - 2486415 - CVE-2026-43951 httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVEs CVE-2024-42516 CVE-2026-28780 CVE-2026-29167 CVE-2026-29169 CVE-2026-33007 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059 CVE-2026-34355 CVE-2026-34356 CVE-2026-42536 CVE-2026-43951 CVE-2026-44185 CVE-2026-44186 CVE-2026-44631 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM httpd-2.4.62-4.el9_6.6.src.rpm SHA-256: fdc92b781a12ca73c2ca9c85deb40dcd58a105195bb6bc6484b4ae8bf1f97cfc x86_64 httpd-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: b2b10675f3f2ead8b790ad9c7be402b284a03c2debef70ae9032a246cb216e89 httpd-core-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: d22b2f594b1eeb66262d99625a0d2f0cd472829ee58f44e5af8b18edf998e4e5 httpd-core-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 07453e8117abb31c6a5fe937f8bea0f8838e2e93ef150ba08fbc8f9915ad6779 httpd-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 746f237ea80c95061ac378b8b9f979c7fec43fb55f7db63112eb1a20e0d606d5 httpd-debugsource-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 5ee99eebba46fefc594f9cc281a2a719478a64aa1ad438989de529f34f477d12 httpd-devel-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 217be8f215b37df27aed5cc6a0c6b57bc41b0cea68633e60ff8cfb4dfac4d48e httpd-filesystem-2.4.62-4.el9_6.6.noarch.rpm SHA-256: 62eaab6790d9a3c7b78dc4317b9de0fb358c18e7729ba519b6e5ae29e099b236 httpd-manual-2.4.62-4.el9_6.6.noarch.rpm SHA-256: c546d435662ed00958f7e9e0b5f9f2e2e884e0de3efdeae1fba921064d375bdf httpd-tools-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 5ad1f2ce9da90a66839a6ecbd046ec4e0f2cdf376c1e811d18453ffdd67b411f httpd-tools-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 780cd0a6c4c5b9bb390519ae83678eba06a180ac3afbf7d62f1d311f10843dbc mod_ldap-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: d0f65780681c013a0fbc9c3ebf4a10f8a5edec5a22e36e2c6a629608caaaa5b6 mod_ldap-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 275b9cd03f73b0dbd5e33817113407da092cd37acc80c34134eab6be2525d80c mod_lua-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 8e39c952cf8f43a5e7fef68cbe89fd0fda7c6933f711163163d0f28c0ed77546 mod_lua-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 8028a25976639d0992c167cebea791ee4deb7b718ce6d40b7958a13298ff4ff6 mod_proxy_html-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 3de06642efc435530f04fc8c7afedb5e781158c2fcc551ae0f3ad16c07700321 mod_proxy_html-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 4637f8dd2b282e61414a285312a879f161278fcc443ae45477406f40df92cf58 mod_session-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 4a95bfeda784ac7ea02df9d91b8fc1486e877b2694f9c32327136f09d294f8ed mod_session-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 337b6eeb0294a86f344c92dfd8f478a1feecf2c82bcb151d175bc327da7509c4 mod_ssl-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: c1b14e732d2806306b2875c2e20e663296d35fe366385827e6c9af029ebb678f mod_ssl-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: ce46b358337959e3c3d1d242d274223c1b4a239ec792f206a71b9f992639f632 Red Hat Enterprise Linux Server - AUS 9.6 SRPM httpd-2.4.62-4.el9_6.6.src.rpm SHA-256: fdc92b781a12ca73c2ca9c85deb40dcd58a105195bb6bc6484b4ae8bf1f97cfc x86_64 httpd-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: b2b10675f3f2ead8b790ad9c7be402b284a03c2debef70ae9032a246cb216e89 httpd-core-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: d22b2f594b1eeb66262d99625a0d2f0cd472829ee58f44e5af8b18edf998e4e5 httpd-core-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 07453e8117abb31c6a5fe937f8bea0f8838e2e93ef150ba08fbc8f9915ad6779 httpd-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 746f237ea80c95061ac378b8b9f979c7fec43fb55f7db63112eb1a20e0d606d5 httpd-debugsource-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 5ee99eebba46fefc594f9cc281a2a719478a64aa1ad438989de529f34f477d12 httpd-devel-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 217be8f215b37df27aed5cc6a0c6b57bc41b0cea68633e60ff8cfb4dfac4d48e httpd-filesystem-2.4.62-4.el9_6.6.noarch.rpm SHA-256: 62eaab6790d9a3c7b78dc4317b9de0fb358c18e7729ba519b6e5ae29e099b236 httpd-manual-2.4.62-4.el9_6.6.noarch.rpm SHA-256: c546d435662ed00958f7e9e0b5f9f2e2e884e0de3efdeae1fba921064d375bdf httpd-tools-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 5ad1f2ce9da90a66839a6ecbd046ec4e0f2cdf376c1e811d18453ffdd67b411f httpd-tools-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 780cd0a6c4c5b9bb390519ae83678eba06a180ac3afbf7d62f1d311f10843dbc mod_ldap-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: d0f65780681c013a0fbc9c3ebf4a10f8a5edec5a22e36e2c6a629608caaaa5b6 mod_ldap-debuginfo-2.4.62-4.el9_6.6.x86_64.rpm SHA-256: 275b9cd03f73b0dbd5e33817113407da092cd3

Share this article