{"cves":["CVE-2026-29167"],"cvss":0.0,"database_specific":{"severity":"LOW"},"description":"[2.4.63-13.0.1.el10_2.6]\n- Replace index.html with Oracle's index page oracle_index.html.\n\n[2.4.63-13.6]\n- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution\n  or denial of service via use-after-free in mod_ldap per-directory\n  configuration (CVE-2026-29167)\n\n[2.4.63-13.5]\n- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix\n\n[2.4.63-13.4]\n- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow\n  via malicious backend servers (CVE-2026-34356)\n- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow\n  via untrusted content in mod_xml2enc (CVE-2026-42536)\n- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in\n  mod_proxy_html allows security bypass (CVE-2026-34355)\n- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via\n  outbound OCSP requests to attacker-controlled server (CVE-2026-44185)\n- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via\n  crafted regular expressions (CVE-2026-44631)\n- Resolves : RHEL-182581 - httpd: incomplete fix for\n  CVE-2023-38709 (CVE-2024-42516)\n- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted\n  request (CVE-2026-29169)\n- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,\n  CVE-2026-24072, CVE-2026-33006, CVE-2026-43951\n\n[2.4.63-13.1]\n- Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary\n  code execution via heap-based buffer overflow (CVE-2026-28780)\n- Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child\n  process crash (CVE-2026-33007)\n- Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter\n  functions (CVE-2026-33857)\n- Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing\n  null-termination check (CVE-2026-34032)\n- Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory\n  disclosure in ajp_parse_data() (CVE-2026-34059)","id":"ELSA-2026-60004-0","ovalId":"oval:com.oracle.elsa:def:2026600040","source":"oracle_linux","title":"ELSA-2026-60004-0:  httpd security update (LOW)","url":"https://linux.oracle.com/errata/ELSA-2026-60004-0.html"}