elsa-2026-42828

oracle_linux
Description

httpd [2.4.37-65.0.1.8] - Replace index.html with Oracle's index page oracle_index.html [2.4.37-65.8] - Resolves: RHEL-173558 - httpd:2.4/httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) - Resolves: RHEL-175074 - httpd:2.4/httpd: NULL pointer dereference can cause a child process crash (CVE-2026-33007) - Resolves: RHEL-175088 - httpd:2.4/httpd: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) - Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) - Resolves: RHEL-175055 - httpd: heap-based buffer over-read and memory disclosure in ajp_parse_data() (CVE-2026-34059) [2.4.37-65.7] - Resolves: RHEL-135054 - httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo (CVE-2025-66200) - Resolves: RHEL-135039 - httpd: Apache HTTP Server: CGI environment variable override (CVE-2025-65082) - Resolves: RHEL-134471 - httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... (CVE-2025-58098) [2.4.37-65.6] - Resolves: RHEL-127073 - mod_ssl: allow more fine grained SSL SNI vhost check to avoid unnecessary 421 errors after CVE-2025-23048 fix - mod_ssl: add conf.d/snipolicy.conf to set 'SSLVHostSNIPolicy authonly' default [2.4.37-65.5] - Resolves: RHEL-99944 - CVE-2025-49812 httpd: HTTP Session Hijack via a TLS upgrade - Resolves: RHEL-99969 - CVE-2024-47252 httpd: insufficient escaping of user-supplied data in mod_ssl - Resolves: RHEL-99961 - CVE-2025-23048 httpd: access control bypass by trusted clients is possible using TLS 1.3 session resumption [2.4.37-65.4] - Resolves: RHEL-87641 - apache Bug 63192 - mod_ratelimit breaks HEAD requests [2.4.37-65.3] - Resolves: RHEL-56068 - Apache HTTPD no longer parse PHP files with unicode characters in the name [2.4.37-65.2] - Resolves: RHEL-46040 - httpd:2.4/httpd: Security issues via backend applications whose response headers are malicious or exploitable (CVE-2024-38476) - Resolves: RHEL-53022 - Regression introduced by CVE-2024-38474 fix [2.4.37-65.1] - Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue in mod_rewrite (CVE-2024-38474) - Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in mod_proxy (CVE-2024-38473) - Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output in mod_rewrite (CVE-2024-38475) - Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference in mod_proxy (CVE-2024-38477) - Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF in mod_rewrite (CVE-2024-39573) [2.4.37-65] - Resolves: RHEL-31857 - httpd:2.4/httpd: HTTP response splitting (CVE-2023-38709) mod_http2 [1.15.7-10.7] - Resolves: RHEL-191279 - mod_http2: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951) [1.15.7-10.6] - Resolves: RHEL-182418 - mod_http2: HTTP/2: Remote Denial of Service via compression bomb and Slowloris-style attack (CVE-2026-49975) [1.15.7-10.5] - Resolves: RHEL-166277 - httpd:2.4/httpd: Apache HTTP Server: HTTP/2 DoS by Memory Increase (CVE-2025-53020) [1.15.7-10.4] - Resolves: RHEL-105186 - httpd:2.4/httpd: untrusted input from a client causes an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630) [1.15.7-10.3] - Resolves: RHEL-58454 - mod_proxy_http2 failures after CVE-2024-38477 fix - Resolves: RHEL-59017 - random failures in other requests on http/2 stream when client resets one request [1.15.7-10.2] - Resolves: RHEL-71575: Wrong Content-Type when proxying using H2 protocol [1.15.7-10.1] - Resolves: RHEL-46214 - Access logs and ErrorDocument don't work when HTTP431 occurs using http/2 on RHEL8 [1.15.7-10] - Resolves: RHEL-29817 - httpd:2.4/mod_http2: httpd: CONTINUATION frames DoS (CVE-2024-27316) [1.15.7-9.3] - Resolves: RHEL-13367 - httpd:2.4/mod_http2: reset requests exhaust memory (incomplete fix of CVE-2023-44487)(CVE-2023-45802) [1.15.7-8.3] - Resolves: #2177748 - CVE-2023-25690 httpd:2.4/httpd: HTTP request splitting with mod_rewrite and mod_proxy mod_md [1:2.0.8-8.2] - Resolves: RHEL-134487 - httpd:2.4/httpd: Apache HTTP Server: mod_md (ACME), unintended retry intervals (CVE-2025-55753) [1:2.0.8-8] - Resolves: #1832844 - mod_md does not work with ACME server that does not provide keyChange or revokeCert resources [1:2.0.8-7] - Resolves: #1747912 - add a2md(1) documentation [1:2.0.8-6] - Resolves: #1781263 - mod_md ACMEv1 crash [1:2.0.8-5] - Resolves: #1747898 - add mod_md package [1:2.0.8-4] - require mod_ssl, update package description [1:2.0.8-3] - rebuild against 2.4.41 [1:2.0.8-2] - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild [1:2.0.8-1] - update to 2.0.8 [2.0.3-1] - Initial import (#1719248).

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2024-42516",
    "CVE-2026-29169",
    "CVE-2026-34355",
    "CVE-2026-34356",
    "CVE-2026-42536",
    "CVE-2026-43951",
    "CVE-2026-44185",
    "CVE-2026-44186",
    "CVE-2026-44631"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "httpd\n[2.4.37-65.0.1.8]\n- Replace index.html with Oracle's index page oracle_index.html\n\n[2.4.37-65.8]\n- Resolves: RHEL-173558 - httpd:2.4/httpd: Apache HTTP Server mod_proxy_ajp:\n  Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780)\n- Resolves: RHEL-175074 - httpd:2.4/httpd: NULL pointer dereference can\n  cause a child process crash (CVE-2026-33007)\n- Resolves: RHEL-175088 - httpd:2.4/httpd: off-by-one out-of-bounds reads\n  in AJP getter functions (CVE-2026-33857)\n- Resolves: RHEL-175620 - httpd:2.4/httpd: NULL pointer dereference via\n  specially crafted request (CVE-2026-29169)\n- Resolves: RHEL-175055 - httpd: heap-based buffer over-read and memory\n  disclosure in ajp_parse_data() (CVE-2026-34059)\n\n[2.4.37-65.7]\n- Resolves: RHEL-135054 - httpd: Apache HTTP Server: mod_userdir+suexec bypass\n  via AllowOverride FileInfo (CVE-2025-66200)\n- Resolves: RHEL-135039 - httpd: Apache HTTP Server: CGI environment variable\n  override (CVE-2025-65082)\n- Resolves: RHEL-134471 - httpd: Apache HTTP Server: Server Side Includes adds\n  query string to #exec cmd=... (CVE-2025-58098)\n\n[2.4.37-65.6]\n- Resolves: RHEL-127073 - mod_ssl: allow more fine grained SSL SNI vhost check\n  to avoid unnecessary 421 errors after CVE-2025-23048 fix\n- mod_ssl: add conf.d/snipolicy.conf to set 'SSLVHostSNIPolicy authonly' default\n\n[2.4.37-65.5]\n- Resolves: RHEL-99944 - CVE-2025-49812 httpd: HTTP Session Hijack via a TLS upgrade\n- Resolves: RHEL-99969 - CVE-2024-47252 httpd: insufficient escaping of\n  user-supplied data in mod_ssl\n- Resolves: RHEL-99961 - CVE-2025-23048 httpd: access control bypass by trusted\n  clients is possible using TLS 1.3 session resumption\n\n[2.4.37-65.4]\n- Resolves: RHEL-87641 - apache Bug 63192 - mod_ratelimit breaks HEAD requests\n\n[2.4.37-65.3]\n- Resolves: RHEL-56068 - Apache HTTPD no longer parse PHP files with\n  unicode characters in the name\n\n[2.4.37-65.2]\n- Resolves: RHEL-46040 - httpd:2.4/httpd: Security issues via backend\n  applications whose response headers are malicious or exploitable (CVE-2024-38476)\n- Resolves: RHEL-53022 - Regression introduced by CVE-2024-38474 fix\n\n[2.4.37-65.1]\n- Resolves: RHEL-45812 - httpd:2.4/httpd: Substitution encoding issue\n  in mod_rewrite (CVE-2024-38474)\n- Resolves: RHEL-45785 - httpd:2.4/httpd: Encoding problem in\n  mod_proxy (CVE-2024-38473)\n- Resolves: RHEL-45777 - httpd:2.4/httpd: Improper escaping of output\n  in mod_rewrite (CVE-2024-38475)\n- Resolves: RHEL-45758 - httpd:2.4/httpd: null pointer dereference\n  in mod_proxy (CVE-2024-38477)\n- Resolves: RHEL-45743 - httpd:2.4/httpd: Potential SSRF\n  in mod_rewrite (CVE-2024-39573)\n\n[2.4.37-65]\n- Resolves: RHEL-31857 - httpd:2.4/httpd: HTTP response\n  splitting (CVE-2023-38709)\n\nmod_http2\n[1.15.7-10.7]\n- Resolves: RHEL-191279 - mod_http2: Apache HTTP Server: Out-of-bounds\n  Read in mod_headers and mod_mime (CVE-2026-43951)\n\n[1.15.7-10.6]\n- Resolves: RHEL-182418 - mod_http2: HTTP/2: Remote Denial of Service via\n  compression bomb and Slowloris-style attack (CVE-2026-49975)\n\n[1.15.7-10.5]\n- Resolves: RHEL-166277 - httpd:2.4/httpd: Apache HTTP Server: HTTP/2 DoS by\n  Memory Increase (CVE-2025-53020)\n\n[1.15.7-10.4]\n- Resolves: RHEL-105186 - httpd:2.4/httpd: untrusted input from a client causes\n  an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)\n\n[1.15.7-10.3]\n- Resolves: RHEL-58454 - mod_proxy_http2 failures after CVE-2024-38477 fix\n- Resolves: RHEL-59017 - random failures in other requests on http/2 stream\n  when client resets one request\n\n[1.15.7-10.2]\n- Resolves: RHEL-71575: Wrong Content-Type when proxying using H2 protocol\n\n[1.15.7-10.1]\n- Resolves: RHEL-46214 - Access logs and ErrorDocument don't work when HTTP431\n  occurs using http/2 on RHEL8\n\n[1.15.7-10]\n- Resolves: RHEL-29817 - httpd:2.4/mod_http2: httpd: CONTINUATION frames\n  DoS (CVE-2024-27316)\n\n[1.15.7-9.3]\n- Resolves: RHEL-13367 - httpd:2.4/mod_http2: reset requests exhaust memory\n  (incomplete fix of CVE-2023-44487)(CVE-2023-45802)\n\n[1.15.7-8.3]\n- Resolves: #2177748 - CVE-2023-25690 httpd:2.4/httpd: HTTP request splitting\n  with mod_rewrite and mod_proxy\n\nmod_md\n[1:2.0.8-8.2]\n- Resolves: RHEL-134487 - httpd:2.4/httpd: Apache HTTP Server: mod_md (ACME),\n  unintended retry intervals (CVE-2025-55753)\n\n[1:2.0.8-8]\n- Resolves: #1832844 - mod_md does not work with ACME server that does not\n  provide keyChange or revokeCert resources\n\n[1:2.0.8-7]\n- Resolves: #1747912 - add a2md(1) documentation\n\n[1:2.0.8-6]\n- Resolves: #1781263 - mod_md ACMEv1 crash\n\n[1:2.0.8-5]\n- Resolves: #1747898 - add mod_md package\n\n[1:2.0.8-4]\n- require mod_ssl, update package description\n\n[1:2.0.8-3]\n- rebuild against 2.4.41\n\n[1:2.0.8-2]\n- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild\n\n[1:2.0.8-1]\n- update to 2.0.8\n\n[2.0.3-1]\n- Initial import (#1719248).",
  "id": "ELSA-2026-42828",
  "ovalId": "oval:com.oracle.elsa:def:202642828",
  "source": "oracle_linux",
  "title": "ELSA-2026-42828:  httpd:2.4 security, bug fix, and enhancement update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-42828.html"
}
View JSON API Download JSON