elsa-2026-41906

oracle_linux
Description

[2.4.62-13.0.1.el9_8.5] - Replace index.html with Oracle's index page oracle_index.html. [2.4.62-13.5] - Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix [2.4.62-13.4] - Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) - Resolves: RHEL-182578 - httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) - Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951, CVE-2026-44119, CVE-2026-44186 [2.4.62-13.3] - Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling vulnerability (CVE-2026-34355) - Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery (CVE-2026-29169) - Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto (CVE-2026-42536) - Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement bug in mod_ssl (CVE-2026-44185) [2.4.62-13.2] - Resolves: RHEL-184312 - httpd: ap_regname restrict to reasonable captures (CVE-2026-44631) [2.4.62-13.1] - Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) - Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child process crash (CVE-2026-33007) - Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) - Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) - Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059)

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2024-42516",
    "CVE-2026-24072",
    "CVE-2026-29169",
    "CVE-2026-33006",
    "CVE-2026-34355",
    "CVE-2026-34356",
    "CVE-2026-42535",
    "CVE-2026-42536",
    "CVE-2026-43951",
    "CVE-2026-44119",
    "CVE-2026-44185",
    "CVE-2026-44186",
    "CVE-2026-44631"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[2.4.62-13.0.1.el9_8.5]\n- Replace index.html with Oracle's index page oracle_index.html.\n\n[2.4.62-13.5]\n- Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix\n\n[2.4.62-13.4]\n- Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow\n  via malicious backend servers (CVE-2026-34356)\n- Resolves: RHEL-182578 - httpd: incomplete fix\n  for CVE-2023-38709 (CVE-2024-42516)\n- Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951,\n  CVE-2026-44119, CVE-2026-44186\n\n[2.4.62-13.3]\n- Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling\n  vulnerability (CVE-2026-34355)\n- Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery\n  (CVE-2026-29169)\n- Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto\n  (CVE-2026-42536)\n- Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement\n  bug in mod_ssl (CVE-2026-44185)\n\n[2.4.62-13.2]\n- Resolves: RHEL-184312 - httpd: ap_regname restrict to reasonable captures\n  (CVE-2026-44631)\n\n[2.4.62-13.1]\n- Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary\n  code execution via heap-based buffer overflow (CVE-2026-28780)\n- Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child\n  process crash (CVE-2026-33007)\n- Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter\n  functions (CVE-2026-33857)\n- Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing\n  null-termination check (CVE-2026-34032)\n- Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory\n  disclosure in ajp_parse_data() (CVE-2026-34059)",
  "id": "ELSA-2026-41906",
  "ovalId": "oval:com.oracle.elsa:def:202641906",
  "source": "oracle_linux",
  "title": "ELSA-2026-41906:  httpd security, bug fix, and enhancement update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-41906.html"
}
View JSON API Download JSON