[ubuntu/jammy-security] apache2 2.4.52-1ubuntu4.23 (Accepted)
Marc Deslauriers
marc.deslauriers at canonical.com
Wed Jul 8 13:33:05 UTC 2026
apache2 (2.4.52-1ubuntu4.23) jammy-security; urgency=medium
* SECURITY UPDATE: mod_ldap per-dir use-after-free
- debian/patches/CVE-2026-29167.patch: Fix inheritance in per-dir context
in modules/ldap/util_ldap.c.
- CVE-2026-29167
* SECURITY UPDATE: mod_proxy_ftp XSS
- debian/patches/CVE-2026-29170.patch: Use ap_os_escape_path() with
ap_escape_html() instead of ap_escape_uri() for href attributes in
generated directory listing links in modules/proxy/mod_proxy_ftp.c.
- CVE-2026-29170
* SECURITY UPDATE: mod_proxy_html buffer overflow
- debian/patches/CVE-2026-34355.patch: Simplify to use the ap_varbuf API
in modules/filters/mod_proxy_html.c.
- CVE-2026-34355
* SECURITY UPDATE: ProxyPassReverseCookieMap buffer overflow
- debian/patches/CVE-2026-34356.patch: fix dup path/domain in
modules/proxy/proxy_util.c.
- CVE-2026-34356
* SECURITY UPDATE: mod_dav_fs protected directory access
- debian/patches/CVE-2026-42535.patch: disallow DAV_FS_STATE_DIR in
modules/dav/fs/repos.c.
- CVE-2026-42535
* SECURITY UPDATE: mod_xml2enc heap overflow
- debian/patches/CVE-2026-42536.patch: Fix accounting in
modules/filters/mod_xml2enc.c.
- CVE-2026-42536
* SECURITY UPDATE: OOB Read in 'merge_response_headers' can cause crash
- debian/patches/CVE-2026-43951.patch: fix lang iteration in
modules/http/http_filters.c, modules/http2/h2_c2_filter.c.
- CVE-2026-43951
* SECURITY UPDATE: escalation of privilege through expressions in .htaccess
in multiple modules
- debian/patches/CVE-2026-44119.patch: restrict per-dir file funcs
centrally in include/ap_expr.h, modules/mappers/mod_rewrite.c,
modules/metadata/mod_setenvif.c, modules/proxy/mod_proxy_fcgi.c,
server/util_expr_eval.c.
- CVE-2026-44119
* SECURITY UPDATE: Stack Buffer Over-Read in mod_ssl OCSP 'send_request'
- debian/patches/CVE-2026-44185.patch: Increase wbuf with the len read by
apr_socket_send: in modules/ssl/ssl_util_ocsp.c.
- CVE-2026-44185
* SECURITY UPDATE: Loop in 'proxy_ftp_handler' in mod_proxy_ftp
- debian/patches/CVE-2026-44186.patch: fix iteration in
modules/proxy/mod_proxy_ftp.c.
- CVE-2026-44186
* SECURITY UPDATE: Heap Underflow in 'ap_regname' via Signed Char Overflow
- debian/patches/CVE-2026-44631.patch: restrict to reasonable captures in
include/ap_regex.h, modules/proxy/mod_proxy.c, server/core.c,
server/util_pcre.c.
- CVE-2026-44631
* SECURITY UPDATE: mod_http2 memory corruption when file handles exhausted
- debian/patches/CVE-2026-48913.patch: update to version 2.0.42 of the
http2 module in modules/http2/*.
- debian/patches/CVE-2026-48913-2.patch: fix buffer overflow in link
mapping in modules/http2/h2_proxy_util.c.
- CVE-2026-48913
* Updated perl-framework tests for security changes:
- debian/perl-framework/t/apache/expr.t
- https://github.com/apache/httpd-tests/commit/c45f32cd44cf15aca0253dc480fe687b2e4d76ff
Date: 2026-07-07 18:24:17.244315+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.23
-------------- next part --------------
Sorry, changesfile not available.
More information about the jammy-changes
mailing list