1 week 1 day ago
USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was
incomplete due to a missing library symbol, resulting in a regression
that could cause Apache HTTP Server to fail to start when HTTP/2
proxying was enabled. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-33007)
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
(CVE-2026-33523)
Elhanan Haenel discovered that Apache HTTP Server incorrectly handled
certain memory operations in mod_proxy_ajp. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-33857)
Tianshuo Han and Jérôme Djouder discovered that Apache HTTP Server
incorrectly handled certain string operations in mod_proxy_ajp. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-34032)
It was discovered that Apache HTTP Server's mod_proxy_html module
incorrectly handled certain content from an untrusted backend. A remote
attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34355)
It was discovered that Apache HTTP Server incorrectly handled
ProxyPassReverseCookie directives with a malicious backend server. A
remote attacker could possibly use this issue to cause a denial of service.
(CVE-2026-34356)
It was discovered that Apache HTTP Server's mod_dav_fs module incorrectly
handled certain path operations. An authenticated user could possibly use
this issue to manipulate trusted WebDAV property databases or cause a
denial of service. (CVE-2026-42535)
It was discovered that Apache HTTP Server's mod_xml2enc module incorrectly
handled certain content from an untrusted backend. A remote attacker could
possibly use this issue to cause a denial of service. (CVE-2026-42536)
It was discovered that Apache HTTP Server incorrectly handled response
headers when multiple content languages were configured. A remote
attacker could possibly use this issue to obtain sensitive information.
(CVE-2026-43951)
It was discovered that Apache HTTP Server incorrectly restricted certain
file functions in expressions within .htaccess files. A local attacker
with .htaccess write access could possibly use this issue to obtain
sensitive information. (CVE-2026-44119)
It was discovered that Apache HTTP Server's mod_ssl module incorrectly
handled OCSP responses from an attacker-controlled server. A remote
attacker could possibly use this issue to obtain sensitive information or
cause a denial of service. (CVE-2026-44185)
It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled responses from an attacker-controlled backend FTP
server. A remote attacker could possibly use this issue to cause a denial
of service. (CVE-2026-44186)
It was discovered that Apache HTTP Server incorrectly handled crafted
regular expressions in the server configuration. An attacker could
possibly use this issue to execute arbitrary code or cause a denial of
service. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-44631)
It was discovered that Apache HTTP Server's mod_http2 module had a
use-after-free vulnerability when file handles were exhausted. A remote
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 20.04 LTS. (CVE-2026-48913)
1 week 1 day ago
It was discovered that KissFFT incorrectly handled certain large Fourier
transform sizes on 32-bit architectures. An attacker could possibly use
this issue to cause KissFFT to crash, resulting in a denial of service, or
execute arbitrary code. (CVE-2025-34297)
It was discovered that KissFFT incorrectly handled certain multidimensional
Fourier transform sizes. An attacker could possibly use this issue to cause
KissFFT to crash, resulting in a denial of service, or execute arbitrary
code. (CVE-2026-41445)
1 week 1 day ago
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- Hardware crypto device drivers;
- NVIDIA Tegra memory controller driver;
- Network drivers;
- GFS2 file system;
- OCFS2 file system;
- SMB network file system;
- B.A.T.M.A.N. meshing protocol;
- Ceph Core library;
- IPv4 networking;
- IPv6 networking;
- Netfilter;
- Open vSwitch;
- RxRPC session sockets;
- SCTP protocol;
- TIPC protocol;
(CVE-2026-52914, CVE-2026-52931, CVE-2026-52955, CVE-2026-52958,
CVE-2026-52982, CVE-2026-52986, CVE-2026-52993, CVE-2026-52999,
CVE-2026-53002, CVE-2026-53006, CVE-2026-53010, CVE-2026-53043,
CVE-2026-53045, CVE-2026-53046, CVE-2026-53049, CVE-2026-53055,
CVE-2026-53088, CVE-2026-53151, CVE-2026-53175, CVE-2026-53215,
CVE-2026-53216, CVE-2026-53224, CVE-2026-53246, CVE-2026-53247,
CVE-2026-53260, CVE-2026-53309, CVE-2026-64531)