[CLSA-2025:1757428404] Fix CVE(s): CVE-2025-23048
Type:
security
Severity:
Important
Release date:
2025-09-09 14:33:29 UTC
Description:
* SECURITY UPDATE: access control bypass by trusted clients via TLS 1.3 session resumption - debian/patches/CVE-2025-23048.patch: update SNI validation to fix compatibility issue - CVE-2025-23048
Updated packages:
  • apache2_2.4.18-2ubuntu3.17+tuxcare.els16_amd64.deb
    sha:a04d0728f6076872b1816742af4d6f0327b557fb
  • apache2-bin_2.4.18-2ubuntu3.17+tuxcare.els16_amd64.deb
    sha:a0734d55748ca8654c896b31763f3475fd8509d1
  • apache2-data_2.4.18-2ubuntu3.17+tuxcare.els16_all.deb
    sha:4b1eaa4b7d3952db2b83ff7d47e4dfbea779ae31
  • apache2-dev_2.4.18-2ubuntu3.17+tuxcare.els16_amd64.deb
    sha:3f6c783787193419f799e5154069e76afb0e81a2
  • apache2-doc_2.4.18-2ubuntu3.17+tuxcare.els16_all.deb
    sha:b270e91266f1838b2345c00b8b7b66fc60afc920
  • apache2-suexec-custom_2.4.18-2ubuntu3.17+tuxcare.els16_amd64.deb
    sha:9270b05627798fdcc3f70b40c9ea3b5e129da88a
  • apache2-suexec-pristine_2.4.18-2ubuntu3.17+tuxcare.els16_amd64.deb
    sha:f619ce8e118bbdfa523384c77a251ab49f23939f
  • apache2-utils_2.4.18-2ubuntu3.17+tuxcare.els16_amd64.deb
    sha:d7170340704e56a7be9a3464e1947c389cdbed3a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.