REDHAT-BUG-2486394: Use After Free
Published Jun 8, 2026
·Updated
Use After Free vulnerability in Apache HTTP Server with modldap in per-directory configuration
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to upgrade to version 2.4.68, which fixes the issue.
Affected Software
1 affected component
Apache HTTP Server>=2.4.0<=2.4.67
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache HTTP Serverto a version that resolves this vulnerability.Fixed in 2.4.68
Event History
Jun 8, 2026
Data Sourced
via Red Hat·04:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
Which configurations are affected?
The issue affects Apache HTTP Server deployments that use mod_ldap in per-directory configuration. The affected version range is 2.4.0 through 2.4.67.
2
What remediation is recommended?
Upgrade Apache HTTP Server to version 2.4.68, which fixes the vulnerability.