RHSA-2026:62165: Important: httpd security update
Important: httpd security update
Other sources
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.Security Fix(es): httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) httpd: modproxyajp: heap-based buffer over-read and memory disclosure in ajpparsedata() (CVE-2026-34059) httpd: modproxyajp: heap-based buffer over-read due to missing null-termination check (CVE-2026-34032) httpd: modproxyajp: off-by-one out-of-bounds reads in AJP getter functions (CVE-2026-33857) httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) httpd: modauthnsocache: NULL pointer dereference can cause a child process crash (CVE-2026-33007) Apache HTTP Server: modproxyajp: Apache HTTP Server modproxyajp: Arbitrary code execution via heap-based buffer overflow (CVE-2026-28780) httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in modldap per-directory configuration (CVE-2026-29167) httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185) httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631) httpd: Apache HTTP Server: Denial of Service in modproxyftp via attacker-controlled FTP server (CVE-2026-44186) httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in modxml2enc (CVE-2026-42536) httpd: Apache HTTP Server: Buffer overflow in modproxyhtml allows security bypass (CVE-2026-34355) httpd: Apache HTTP Server: Out-of-bounds Read in modheaders and modmime (CVE-2026-43951) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-coreto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-filesystemto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-manualto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-coreto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-core-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-debugsourceto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-develto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-toolsto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa - Upgrade
Upgrade
redhat/httpd-tools-debuginfoto a version that resolves this vulnerability.Fixed in 2.4.62-4.el9_6.6.aa
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize systems running the listed Red Hat httpd packages, especially where mod_proxy_ajp or mod_ldap is enabled. The update also addresses issues in mod_authn_socache and in httpd request handling.
What attacker-controlled inputs are identified in the affected issues?
The advisory identifies specially crafted requests, malicious backend servers, and attacker-controlled servers used for outbound OCSP requests. Several issues are specifically associated with mod_proxy_ajp processing.
What is the potential impact if the affected components are exposed?
The listed fixes include arbitrary code execution, denial of service through crashes or NULL pointer dereferences, memory disclosure through buffer over-reads, and out-of-bounds or use-after-free memory errors.