[ubuntu/noble-security] apache2 2.4.58-1ubuntu8.15 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Wed Jul 8 13:33:04 UTC 2026


apache2 (2.4.58-1ubuntu8.15) noble-security; urgency=medium

  * SECURITY UPDATE: mod_ldap per-dir use-after-free
    - debian/patches/CVE-2026-29167.patch: Fix inheritance in per-dir context
      in modules/ldap/util_ldap.c.
    - CVE-2026-29167
  * SECURITY UPDATE: mod_proxy_ftp XSS
    - debian/patches/CVE-2026-29170.patch: Use ap_os_escape_path() with
      ap_escape_html() instead of ap_escape_uri() for href attributes in
      generated directory listing links in modules/proxy/mod_proxy_ftp.c.
    - CVE-2026-29170
  * SECURITY UPDATE: mod_proxy_html buffer overflow
    - debian/patches/CVE-2026-34355.patch: Simplify to use the ap_varbuf API
      in modules/filters/mod_proxy_html.c.
    - CVE-2026-34355
  * SECURITY UPDATE: ProxyPassReverseCookieMap buffer overflow
    - debian/patches/CVE-2026-34356.patch: fix dup path/domain in
      modules/proxy/proxy_util.c.
    - CVE-2026-34356
  * SECURITY UPDATE: mod_dav_fs protected directory access
    - debian/patches/CVE-2026-42535.patch: disallow DAV_FS_STATE_DIR in
      modules/dav/fs/repos.c.
    - CVE-2026-42535
  * SECURITY UPDATE: mod_xml2enc heap overflow
    - debian/patches/CVE-2026-42536.patch: Fix accounting in
      modules/filters/mod_xml2enc.c.
    - CVE-2026-42536
  * SECURITY UPDATE: OOB Read in 'merge_response_headers' can cause crash
    - debian/patches/CVE-2026-43951.patch: fix lang iteration in
      modules/http/http_filters.c, modules/http2/h2_c2_filter.c.
    - CVE-2026-43951
  * SECURITY UPDATE: escalation of privilege through expressions in .htaccess
    in multiple modules
    - debian/patches/CVE-2026-44119.patch: restrict per-dir file funcs
      centrally in include/ap_expr.h, modules/mappers/mod_rewrite.c,
      modules/metadata/mod_setenvif.c, modules/proxy/mod_proxy_fcgi.c,
      server/util_expr_eval.c.
    - CVE-2026-44119
  * SECURITY UPDATE: Stack Buffer Over-Read in mod_ssl OCSP 'send_request'
    - debian/patches/CVE-2026-44185.patch: Increase wbuf with the len read by
      apr_socket_send: in modules/ssl/ssl_util_ocsp.c.
    - CVE-2026-44185
  * SECURITY UPDATE: Loop in 'proxy_ftp_handler' in mod_proxy_ftp
    - debian/patches/CVE-2026-44186.patch: fix iteration in
      modules/proxy/mod_proxy_ftp.c.
    - CVE-2026-44186
  * SECURITY UPDATE: Heap Underflow in 'ap_regname' via Signed Char Overflow
    - debian/patches/CVE-2026-44631.patch: restrict to reasonable captures in
      include/ap_regex.h, modules/proxy/mod_proxy.c, server/core.c,
      server/util_pcre.c.
    - CVE-2026-44631
  * SECURITY UPDATE: mod_http2 memory corruption when file handles exhausted
    - debian/patches/CVE-2026-48913.patch: update to version 2.0.42 of the
      http2 module in modules/http2/*.
    - debian/patches/CVE-2026-48913-2.patch: fix buffer overflow in link
      mapping in modules/http2/h2_proxy_util.c.
    - CVE-2026-48913
  * Updated perl-framework tests for security changes:
    - debian/perl-framework/t/apache/expr.t
    - debian/perl-framework/t/modules/headers.t
    - https://github.com/apache/httpd-tests/commit/c45f32cd44cf15aca0253dc480fe687b2e4d76ff

Date: 2026-07-07 18:24:32.267145+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.15
-------------- next part --------------
Sorry, changesfile not available.


More information about the noble-changes mailing list