- What: Security update for httpd
- Impact: Red Hat Enterprise Linux 9.2 systems using the Apache HTTP Server
Red Hat Product Errata RHSA-2026:67152 - Security Advisory Issued: 2026-09-14 Updated: 2026-09-14 RHSA-2026:67152 - Security Advisory Overview Updated Packages Synopsis Important: httpd security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for httpd is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059) httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash (CVE-2026-33007) Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration (CVE-2026-29167) httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186) httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2374549 - CVE-2024-42516 httpd: incomplete fix for CVE-2023-38709 BZ - 2464940 - CVE-2026-34059 httpd: mod_proxy_ajp: heap-based buffer over-read and memory disclosure in ajp_parse_data() BZ - 2464952 - CVE-2026-34032 httpd: mod_proxy_ajp: heap-based buffer over-read due to missing null-termination check BZ - 2464953 - CVE-2026-33857 httpd: mod_proxy_ajp: off-by-one out-of-bounds reads in AJP getter functions BZ - 2465296 - CVE-2026-29169 httpd: NULL pointer dereference via specially crafted request BZ - 2465299 - CVE-2026-33007 httpd: mod_authn_socache: NULL pointer dereference can cause a child process crash BZ - 2466913 - CVE-2026-28780 Apache HTTP Server: mod_proxy_ajp: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow BZ - 2486394 - CVE-2026-29167 httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration BZ - 2486395 - CVE-2026-34356 httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers BZ - 2486397 - CVE-2026-44185 httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server BZ - 2486399 - CVE-2026-44631 httpd: Apache HTTP Server: Denial of Service via crafted regular expressions BZ - 2486402 - CVE-2026-44186 httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server BZ - 2486411 - CVE-2026-42536 httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc BZ - 2486414 - CVE-2026-34355 httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass BZ - 2486415 - CVE-2026-43951 httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVEs CVE-2024-42516 CVE-2026-28780 CVE-2026-29167 CVE-2026-29169 CVE-2026-33007 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059 CVE-2026-34355 CVE-2026-34356 CVE-2026-42536 CVE-2026-43951 CVE-2026-44185 CVE-2026-44186 CVE-2026-44631 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM httpd-2.4.53-11.el9_2.15.src.rpm SHA-256: 02904a08cf6298c70024879af822647220c969c4ec356528228ecdf061b8fa06 x86_64 httpd-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 44638973381585a377f420d0c0cde667293fad0843547f9ca618b4b1f2749d5b httpd-core-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 55623b340a98eff2375e7d1b0b74e700d01e285b9d8fd27adc7efc6e6926c066 httpd-core-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 385f76aead3e5a735c5009fc634c7644353d5eeff36561a46768c45c39f67312 httpd-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 039e8133a778651384b6a73d5cbd1b5bfe98c70ac4bdd71ed10185448ea90c2e httpd-debugsource-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 8b2259815ea490cc956b8cd6a88205ab20e9f53f6db6dfcc2efc99695ffe2792 httpd-devel-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: b914b91aaa401974cb57ae20d6fe6c526290edd79b7beea43d25f8ff2476d205 httpd-filesystem-2.4.53-11.el9_2.15.noarch.rpm SHA-256: 4533f35cd635351a8f818dad00b02d2998c88d9eb4e360451196f50e4afe1d7b httpd-manual-2.4.53-11.el9_2.15.noarch.rpm SHA-256: 478d51784e694b14d0a5c09e898a1aeebab032a7a07e3cdef7c0b3d232a13019 httpd-tools-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: ab2a88ccb1bd92bd95971ba619caaef0ba4b643cd26493dfe294177815da77c6 httpd-tools-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: dd3a0853cb20c2fc1fdf2b65794cd3df3113f51118081e3fce3455a3681df62c mod_ldap-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 8a03cd37ea436acb0cc0c587812dd05288e615b617e92443aa5aadc42d4eaa39 mod_ldap-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: a5834bf0b307ba4bf54be1c443cf2f80a32c9b65c72b87ddcbab76928c89cc2d mod_lua-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 095c3886c926f68bf6136a79f8e25effc4bcebed7942f8fb148fd9d746f83aa2 mod_lua-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 59d30a02536613480deaaf15b8705b428fd1fa28ae527206693e480f85a97c2c mod_proxy_html-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: e1e07e2a8fac7eb1141da7c526d2dd82ef949881e46cdc68433cdf694471af99 mod_proxy_html-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 5cee06bb318009c6b75c469abf9828a10e2f566514fce48de4846ec8cc7f7c0d mod_session-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 62e959fae93e59ff68a3e5f824ee2b82b5dd0f8ecdf3b4c269c6fcbaf37c9fc5 mod_session-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: ea96c8e331735d0281cae3b2045e02339b3a3f1d9d537c0ee9430e9d8bad1e78 mod_ssl-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: c719f6d792ec9bc26c7450c8ff62d3a2ff041eb514da4397abb0cae86bc678fa mod_ssl-debuginfo-2.4.53-11.el9_2.15.x86_64.rpm SHA-256: 3a1be3e21a2383b5450c1a076ff3e43a1acca0df12a8ad2389570ba65dae39e4 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM httpd-2.4.53-11.el9_2.15.src.rpm SHA-256: 02904a08cf6298c70024879af822647220c969c4ec356528228ecdf061b8fa06 ppc64le httpd-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 1ea5831e5bd078ba2253d487a346fdd17233792f50b64713b23e87dc25503781 httpd-core-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 7d38cddb1ac328ea86f0481f2496d62a57ef3af4e52a06aae68492d0ad5d55e9 httpd-core-debuginfo-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: ada046dddcf08a4a1c5ec1d0bf8aa2b44dec453d1151208da05bd4bc1703c0c0 httpd-debuginfo-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 4daba5e64ef75ae57ef2c02cc5df0554bc6f594d1edc8ea576e0a29ab676971a httpd-debugsource-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: b4713372691882ada946da0b1d3abf368044ebf432a964f62d0ef840aaffa13f httpd-devel-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 6090dc364e524a06b2af70c242b2e9c2aae37207ba3165ed12aee712996eb729 httpd-filesystem-2.4.53-11.el9_2.15.noarch.rpm SHA-256: 4533f35cd635351a8f818dad00b02d2998c88d9eb4e360451196f50e4afe1d7b httpd-manual-2.4.53-11.el9_2.15.noarch.rpm SHA-256: 478d51784e694b14d0a5c09e898a1aeebab032a7a07e3cdef7c0b3d232a13019 httpd-tools-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 86056e476fdc4194944c5d46229369ca9b62798683bffd773c258f2494d58884 httpd-tools-debuginfo-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: d62d6576bd2f09cbf7238cedc8c99432285b679abeeef556347c90b5378de30b mod_ldap-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 8ac4474fe823e5604feb9206c14cdaaff2ef378c2da5d7235921a85cfe56e07c mod_ldap-debuginfo-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: ab0b1c548d322e0bb491c16d7ce10e0aef3da256046e99ee96cec79662e70e47 mod_lua-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: 47e9e059196cf7fee697ad24c329023069039f32584a4aac1af5dd11dd9d0620 mod_lua-debuginfo-2.4.53-11.el9_2.15.ppc64le.rpm SHA-256: e75ce179