Release date:
2026-05-19 00:19:25 UTC
Description:
* SECURITY UPDATE: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions
- debian/patches/CVE-2026-33857-prereq.patch: prerequisite fix for
ajp_msg_check_header bounds check to keep msg->len within buffer
- debian/patches/CVE-2026-33857.patch: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions
- CVE-2026-33857
* SECURITY UPDATE: fix improper null termination and out-of-bounds read in ajp_msg_get_string
- debian/patches/CVE-2026-34032.patch: fix improper null termination and out-of-bounds read in ajp_msg_get_string
- CVE-2026-34032
* SECURITY UPDATE: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data
- debian/patches/CVE-2026-34059.patch: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data
- CVE-2026-34059
* SECURITY UPDATE: use restricted ap_expr parser in htaccess context to prevent local privilege escalation
- debian/patches/CVE-2026-24072.patch: use restricted ap_expr parser in htaccess context to prevent local privilege escalation
- CVE-2026-24072
* SECURITY UPDATE: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks
- debian/patches/CVE-2026-29169.patch: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks
- CVE-2026-29169
* SECURITY UPDATE: fix timing attack allowing Digest authentication bypass in mod_auth_digest
- debian/patches/CVE-2026-33006.patch: fix timing attack allowing Digest authentication bypass in mod_auth_digest
- CVE-2026-33006
* SECURITY UPDATE: fix NULL pointer dereference crash in mod_authn_socache
- debian/patches/CVE-2026-33007.patch: fix NULL pointer dereference crash in mod_authn_socache
- CVE-2026-33007
* SECURITY UPDATE: fix HTTP response splitting via newlines/controls in outgoing status line
- debian/patches/CVE-2026-33523.patch: fix HTTP response splitting via newlines/controls in outgoing status line
- CVE-2026-33523
Updated packages:
-
apache2_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:096e680c9fb0f06d07808bfb093729ea048b74e7
-
apache2-bin_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:14694b51a73f634338270c8c20f52eda1894dbf7
-
apache2-data_2.4.59-1~deb10u1+tuxcare.els5_all.deb
sha:be315eaabeaea983d88361c0037e489cc709211c
-
apache2-dev_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:386099f3b4ec8626905f8dc6fa3da27e0b88aa67
-
apache2-doc_2.4.59-1~deb10u1+tuxcare.els5_all.deb
sha:fd530b4b62eebe797b3be48883b0ee1ec2336e81
-
apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:7be3c0093dffe41498387470579422833f688b68
-
apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:43b7f479118a9b49e41cb02a4c89e0c0aa7d5257
-
apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:0ae1d5bea5071cb87f6773f456de4143eabb4fee
-
apache2-utils_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:ea411b94e385613ef702d20823a9e0b9fc6d26fb
-
libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:5683fa9c4b7c71c4fcf0fa95a1fc9017b183012d
-
libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
sha:a23a6cd779adb834c73c1bb7e23766eb26c30713
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.