Red Hat Security Advisory: httpd:2.4 security, bug fix, and enhancement update
🔗 CVE IDs covered (9)
📋 Description
CVE-2024-42516 — httpd: incomplete fix for CVE-2023-38709 CVE-2026-29169 — httpd: NULL pointer dereference via specially crafted request CVE-2026-34355 — httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVE-2026-34356 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers CVE-2026-42536 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc CVE-2026-43951 — httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVE-2026-44185 — httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server CVE-2026-44186 — httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server CVE-2026-44631 — httpd: Apache HTTP Server: Denial of Service via crafted regular expressions
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2026:42828
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374549
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2465296
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486395
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486397
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486399
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486402
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486411
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486414
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2486415
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_42828.json