elsa-2026-34109
oracle_linux[2.4.63-13.0.1.el10_2.4] - Replace index.html with Oracle's index page oracle_index.html. [2.4.63-13.4] - Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) - Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536) - Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355) - Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) - Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) - Resolves : RHEL-182581 - httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) - Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) - Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535, CVE-2026-24072, CVE-2026-33006, CVE-2026-43951 [2.4.63-13.1] - Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) - Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child process crash (CVE-2026-33007) - Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) - Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) - Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059)
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2024-42516",
"CVE-2026-29169",
"CVE-2026-34355",
"CVE-2026-34356",
"CVE-2026-42536",
"CVE-2026-44185",
"CVE-2026-44631"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[2.4.63-13.0.1.el10_2.4]\n- Replace index.html with Oracle's index page oracle_index.html.\n\n[2.4.63-13.4]\n- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow\n via malicious backend servers (CVE-2026-34356)\n- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow\n via untrusted content in mod_xml2enc (CVE-2026-42536)\n- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in\n mod_proxy_html allows security bypass (CVE-2026-34355)\n- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via\n outbound OCSP requests to attacker-controlled server (CVE-2026-44185)\n- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via\n crafted regular expressions (CVE-2026-44631)\n- Resolves : RHEL-182581 - httpd: incomplete fix for\n CVE-2023-38709 (CVE-2024-42516)\n- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted\n request (CVE-2026-29169)\n- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,\n CVE-2026-24072, CVE-2026-33006, CVE-2026-43951\n\n[2.4.63-13.1]\n- Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary\n code execution via heap-based buffer overflow (CVE-2026-28780)\n- Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child\n process crash (CVE-2026-33007)\n- Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter\n functions (CVE-2026-33857)\n- Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing\n null-termination check (CVE-2026-34032)\n- Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory\n disclosure in ajp_parse_data() (CVE-2026-34059)",
"id": "ELSA-2026-34109",
"ovalId": "oval:com.oracle.elsa:def:202634109",
"source": "oracle_linux",
"title": "ELSA-2026-34109: httpd security, bug fix, and enhancement update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-34109.html"
}