[CLSA-2026:1779118869] Fix of 8 CVEs
Type:
security
Severity:
Important
Release date:
2026-05-19 00:19:25 UTC
Description:
* SECURITY UPDATE: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions - debian/patches/CVE-2026-33857-prereq.patch: prerequisite fix for ajp_msg_check_header bounds check to keep msg->len within buffer - debian/patches/CVE-2026-33857.patch: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions - CVE-2026-33857 * SECURITY UPDATE: fix improper null termination and out-of-bounds read in ajp_msg_get_string - debian/patches/CVE-2026-34032.patch: fix improper null termination and out-of-bounds read in ajp_msg_get_string - CVE-2026-34032 * SECURITY UPDATE: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data - debian/patches/CVE-2026-34059.patch: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data - CVE-2026-34059 * SECURITY UPDATE: use restricted ap_expr parser in htaccess context to prevent local privilege escalation - debian/patches/CVE-2026-24072.patch: use restricted ap_expr parser in htaccess context to prevent local privilege escalation - CVE-2026-24072 * SECURITY UPDATE: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks - debian/patches/CVE-2026-29169.patch: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks - CVE-2026-29169 * SECURITY UPDATE: fix timing attack allowing Digest authentication bypass in mod_auth_digest - debian/patches/CVE-2026-33006.patch: fix timing attack allowing Digest authentication bypass in mod_auth_digest - CVE-2026-33006 * SECURITY UPDATE: fix NULL pointer dereference crash in mod_authn_socache - debian/patches/CVE-2026-33007.patch: fix NULL pointer dereference crash in mod_authn_socache - CVE-2026-33007 * SECURITY UPDATE: fix HTTP response splitting via newlines/controls in outgoing status line - debian/patches/CVE-2026-33523.patch: fix HTTP response splitting via newlines/controls in outgoing status line - CVE-2026-33523
Updated packages:
  • apache2_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:096e680c9fb0f06d07808bfb093729ea048b74e7
  • apache2-bin_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:14694b51a73f634338270c8c20f52eda1894dbf7
  • apache2-data_2.4.59-1~deb10u1+tuxcare.els5_all.deb
    sha:be315eaabeaea983d88361c0037e489cc709211c
  • apache2-dev_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:386099f3b4ec8626905f8dc6fa3da27e0b88aa67
  • apache2-doc_2.4.59-1~deb10u1+tuxcare.els5_all.deb
    sha:fd530b4b62eebe797b3be48883b0ee1ec2336e81
  • apache2-ssl-dev_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:7be3c0093dffe41498387470579422833f688b68
  • apache2-suexec-custom_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:43b7f479118a9b49e41cb02a4c89e0c0aa7d5257
  • apache2-suexec-pristine_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:0ae1d5bea5071cb87f6773f456de4143eabb4fee
  • apache2-utils_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:ea411b94e385613ef702d20823a9e0b9fc6d26fb
  • libapache2-mod-md_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:5683fa9c4b7c71c4fcf0fa95a1fc9017b183012d
  • libapache2-mod-proxy-uwsgi_2.4.59-1~deb10u1+tuxcare.els5_amd64.deb
    sha:a23a6cd779adb834c73c1bb7e23766eb26c30713
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.