RHSA-2026:60004: Low: httpd security update
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in modldap per-directory configuration (CVE-2026-29167) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-coreto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-coreto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.63-13.el10_2.6.aa - Upgrade
Upgrade
httpdto a version that resolves this vulnerability.Patch CVE-2026-29167
Event History
Frequently Asked Questions
Which installed packages should be included in the remediation scope?
The advisory covers redhat/httpd, redhat/httpd-core, redhat/httpd-core-debuginfo, redhat/httpd-debuginfo, redhat/httpd-debugsource, redhat/httpd-devel, redhat/httpd-tools, and redhat/httpd-tools-debuginfo.
Where can I obtain the CVSS score and additional technical details?
The advisory directs readers to the CVE references for CVSS scoring, impact details, acknowledgments, and related information. The listed references include the Red Hat Bugzilla record and the RHSA erratum.