[CLSA-2026:1767800942] httpd: Fix of CVE-2025-58098
Type:
security
Severity:
Important
Release date:
2026-01-07 15:49:05 UTC
Description:
- CVE-2025-58098: don't pass querry string args as command line arguments to SSI-invoked CGI scripts
Updated packages:
  • httpd-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:ee8f7c172c71b79c5b4f52269596503cf5b75b41a99664e2e4b426d8ddb21be3
  • httpd-devel-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:0ed6150e5c1ca49c4519308cf2f3669f5aae91631cebde88dc2f3bfba37a92a3
  • httpd-filesystem-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.noarch.rpm
    sha:e5c320f31552552985c8e6de2d911d51ec940d348b06f28170dbdcb855f8af41
  • httpd-manual-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.noarch.rpm
    sha:ca1d737e0510f19826a0852109db8b10a3b5d9bbccc0fd35b8dad870cb7a1741
  • httpd-tools-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:816d0d804fbb7a1d1b9df68907b88d384dd74c0cfcd806d76bc2b53ea0946dad
  • mod_ldap-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:73cc3817481eba0405bf6525d77af438c598a511c1778965ceb945d2f5328519
  • mod_proxy_html-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:81a2ad607b5ee27e2ac1d00b002646afdd74c49a641b0c0cf8aa02f29ed738e7
  • mod_session-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:e97c4e508543841561d1bd5e8fc7386b85ebc9ffb47e1ca41c5589b8f954aa27
  • mod_ssl-2.4.37-64.module_el8+2325+f303b1da.tuxcare.els4.x86_64.rpm
    sha:f9fdeddacd4e52cda545ed75be68653fb84278c5381ba8fed305e5b42fb77c5d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.