Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP3 security update
🔗 CVE IDs covered (6)
📋 Description
CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-55753 — mod_md: Apache HTTP Server: mod_md (ACME), unintended retry intervals CVE-2025-58098 — httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... CVE-2025-65082 — httpd: Apache HTTP Server: CGI environment variable override CVE-2025-66200 — httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo CVE-2025-69419 — openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
🎯 Affected products106
- Red Hat JBoss Core Services on RHEL 7 Server
- Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.3-4.el7jbcs.src as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-0:1.6.3-4.el8jbcs.src as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-debuginfo-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-devel-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-devel-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-ldap-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-ldap-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-ldap-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-mysql-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-mysql-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-nss-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-nss-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-odbc-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-odbc-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-openssl-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-openssl-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-openssl-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-pgsql-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-pgsql-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-pgsql-debuginfo-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- jbcs-httpd24-apr-util-sqlite-0:1.6.3-4.el7jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 7 Server
- jbcs-httpd24-apr-util-sqlite-0:1.6.3-4.el8jbcs.x86_64 as a component of Red Hat JBoss Core Services on RHEL 8
- +76 more not shown
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, Red Hat recommends avoiding the processing of PKCS#12 files from untrusted or unverified sources. Applications that use the `PKCS12_get_friendlyname()` API should ensure that PKCS#12 files are only processed if they originate from trusted entities. Restricting the input sources for PKCS#12 files can significantly reduce the attack surface for this flaw.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:2994
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_core_services/2.4.62/html/red_hat_jboss_core_services_apache_http_server_2.4.62_service_pack_3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2396054
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419140
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419262
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430386
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2994.json