Opened 5 months ago

Closed 4 months ago

#23251 closed enhancement (fixed)

httpd-2.4.67

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Joe Locash, 5 months ago

Priority: normal → high

CVE's fixed in this release:

  • important: Apache HTTP Server: http2: double free and possible RCE on early reset (CVE-2026-23918)
  • moderate: Apache HTTP Server: mod_rewrite elevation of privileges via ap_expr (CVE-2026-24072)
  • low: Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header() (CVE-2026-28780)
  • low: Apache HTTP Server: mod_md unrestricted OCSP response (CVE-2026-29168)
  • low: Apache HTTP Server: mod_dav_lock indirect lock crash (CVE-2026-29169)
  • moderate: Apache HTTP Server: mod_auth_digest timing attack (CVE-2026-33006)
  • low: Apache HTTP Server: mod_authn_socache crash (CVE-2026-33007)
  • low: Apache HTTP Server: multiple modules: HTTP response splitting forwarding malicious status line (CVE-2026-33523)
  • low: Apache HTTP Server: Off-by-one OOB reads in AJP getter functions (CVE-2026-33857)
  • low: Apache HTTP Server: mod_proxy_ajp: Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string) (CVE-2026-34032)
  • low: Apache HTTP Server: mod_proxy_ajp: Heap Over-Read and memory disclosure in ajp_parse_data() (CVE-2026-34059)

​https://httpd.apache.org/security/vulnerabilities_24.html

Changes with Apache 2.4.67

  *) mod_md: update to version 2.6.10
     - Fix issue #420 <https://github.com/icing/mod_md/issues/420> by ignoring
       job.json files that claim to have completely finished a certificate
       renewal, but have not produced the necessary result files.

  *) mod_http2: update to version 2.0.39
     Remove streams own memory allocator after reports of memory problems
     with third party modules.
     [Stefan Eissing]

  *) mod_http2: update to version 2.0.38
     Source sync with mod_h2 github repository. No functional change.
     [Stefan Eissing]

  *) Updated conf/mime.types: added vnd.sqlite3, HEIC, HEIF
     [Alexandru Mărășteanu <hello alexei.ro>]

  *) mod_md: update to version 2.6.7
     - Fix a regression in `MDStapleOthers` which broke in v2.6.0 and no longer
       applied, no matter the configuration.

  *) mod_md: update to version 2.6.9
     - Pebble 2.9+ reports another error when terms of service agreement is
       not set. Treating all "userActionRequired" errors as permanent now.

  *) mod_md: update to version 2.6.8
     - Fix the ARI related `replaces` property in ACME order creation to only
       be used when the CA supports ARI and it is enabled in the menu config.
     - Fix compatibility with APR versions before 1.6.0 which do not have
       `apr_cstr_casecmp` and should use `apr_strnatcasecmp` instead.

  *) mod_http2: update to version 2.0.37
     Prevent double purge of a stream, resulting in a double free.
     Fixes PR 69899.
     [Stefan Eissing]

  *) mod_md: Use correct function name when compiling against APR < 1.6.0.
     PR 69954 [Tần Quảng <baobaoxich@gmail.com>]

comment:2 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 5 months ago

Fixed at 838ce118c5. Leaving open for SA.

comment:4 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

comment:5 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-079 issued

Note: See TracTickets for help on using tickets.