[CLSA-2026:1779118679] Fix of 8 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-18 15:38:03 UTC
Description:
* SECURITY UPDATE: mod_proxy_ajp heap buffer over-read in ajp_msg_get_string - debian/patches/CVE-2026-34032.patch: add buffer checks in modules/proxy/ajp_msg.c. - CVE-2026-34032 * SECURITY UPDATE: AJP getter functions off-by-one out-of-bounds reads - debian/patches/CVE-2026-33857.patch: fix length checks in AJP msg_get functions in modules/proxy/ajp_msg.c. - CVE-2026-33857 * SECURITY UPDATE: mod_proxy_ajp heap over-read in ajp_parse_data - debian/patches/CVE-2026-34059.patch: fix message length check in modules/proxy/ajp_header.c. - CVE-2026-34059 * SECURITY UPDATE: mod_authn_socache crash in caching forward proxy - debian/patches/CVE-2026-33007.patch: validate URL earlier in modules/aaa/mod_authn_socache.c. - CVE-2026-33007 * SECURITY UPDATE: HTTP response splitting via malicious backend status line - debian/patches/CVE-2026-33523.patch: scan outgoing status line for newlines and controls in modules/http/http_filters.c. - CVE-2026-33523 * SECURITY UPDATE: mod_rewrite elevation of privileges via ap_expr in .htaccess - debian/patches/CVE-2026-24072.patch: use AP_EXPR_FLAG_RESTRICTED in htaccess context in modules/mappers/mod_rewrite.c, modules/metadata/mod_setenvif.c, modules/proxy/mod_proxy_fcgi.c. - CVE-2026-24072 * SECURITY UPDATE: mod_auth_digest timing attack allowing Digest auth bypass - debian/patches/CVE-2026-33006.patch: use apr_crypto_equals (constant- time comparison) for nonce hash and digest checks, add VALID_NONCE validation and MD5_DIGEST_LEN length check in get_digest_rec, in modules/aaa/mod_auth_digest.c. Bumps configure.in apr-util requirement to >= 1.6 (bionic ships 1.6.1). - CVE-2026-33006 * SECURITY UPDATE: mod_proxy_ajp ajp_msg_check_header bounds-check fix - debian/patches/CVE-2026-28780.patch: tighten the upper-bound check in ajp_msg_check_header() to reserve AJP_HEADER_LEN bytes of headroom in modules/proxy/ajp_msg.c (companion to CVE-2026-33857/34032). - CVE-2026-28780
Updated packages:
  • apache2_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:d1d1c309999f9abc9fdd0106b632524f197e7e1e
  • apache2-bin_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:f65bd8ade3204d1710463d348408f047d313e8bf
  • apache2-data_2.4.29-1ubuntu4.27+tuxcare.els9_all.deb
    sha:786f0763503dff1f7c3c0debea57c525825e1378
  • apache2-dev_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:d8fb7cdf670bb7e320895ab8129552e7a7b25ee6
  • apache2-doc_2.4.29-1ubuntu4.27+tuxcare.els9_all.deb
    sha:4bcd525175fb6894b6ee7fcec46d8a11494d722d
  • apache2-ssl-dev_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:7bb416d46bc8e4219e7fb8f6d8e276e07ac3fac4
  • apache2-suexec-custom_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:e8299b4ab542899ed35dd7de333bc4a98b4c3de9
  • apache2-suexec-pristine_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:bc7057caef0e77adc4e481c6558799f033743917
  • apache2-utils_2.4.29-1ubuntu4.27+tuxcare.els9_amd64.deb
    sha:7be23d546cc8c42f5e10c9dcc9048ead77b8285c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.