[ubuntu/resolute-security] apache2 2.4.66-2ubuntu2.5 (Accepted)

Kyle Kernick kyle.kernick at canonical.com
Wed Oct 7 17:14:00 UTC 2026


apache2 (2.4.66-2ubuntu2.5) resolute-security; urgency=medium

  * SECURITY UPDATE: Use after free in mod_rewrite.
    - debian/patches/CVE-2026-56154.patch: Copy lookahead value in
      modules/mappers/mod_rewrite.c
    - CVE-2026-56154
  * SECURITY UPDATE: Use after free in mod_http2
    - debian/patches/CVE-2026-57941.patch: Careful handling of session bbtmp
      in modules/http2/h2_c1_io.c, ../h2_mplx.c, ../h2_mplx.h,
      ../h2_session.c, and ../h2_stream.h
    - CVE-2026-57941
  * SECURITY UPDATE: Improper privilege management in mod_ssl
    - debian/patches/CVE-2026-59797.patch: Don't expose file funcs in
      modules/ssl/ssl_engine_config.c
    - CVE-2026-59797

Date: 2026-10-05 20:34:23.927037+00:00
Changed-By: Kyle Kernick <kyle.kernick at canonical.com>
https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list