RHSA-2026:59347: Low: httpd security update
Low: httpd security update
Other sources
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in modldap per-directory configuration (CVE-2026-29167) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-coreto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-coreto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-13.el9_8.6.aa - Compensating control
If you cannot immediately update httpd to a fixed version, mitigate the impact of CVE-2026-29167 by restricting or disabling mod_ldap usage (per-directory configuration that can trigger the mod_ldap use-after-free) until the httpd security update is applied.