ELBA-2025-23372

ELBA-2025-23372 - httpd:2.4 bug fix and enhancement update

Type:BUG
Impact:NA
Release Date:2025-12-24

Description


httpd
[2.4.37-65.5.0.1]
- Replace index.html with Oracle's index page oracle_index.html

[2.4.37-65.5]
- Resolves: RHEL-99944 - CVE-2025-49812 httpd: HTTP Session Hijack via a TLS upgrade
- Resolves: RHEL-99969 - CVE-2024-47252 httpd: insufficient escaping of
user-supplied data in mod_ssl
- Resolves: RHEL-99961 - CVE-2025-23048 httpd: access control bypass by trusted
clients is possible using TLS 1.3 session resumption

mod_http2
[1.15.7-10.4]
- Resolves: RHEL-105186 - httpd:2.4/httpd: untrusted input from a client causes
an assertion to fail in the Apache mod_proxy_http2 module (CVE-2025-49630)

mod_md
[1:2.0.8-8]
- Resolves: #1832844 - mod_md does not work with ACME server that does not
provide keyChange or revokeCert resources




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (aarch64) mod_http2-1.15.7-10.module+el8.10.0+90652+bef864ba.4.src.rpmb5447e310ce463e53bdf76d4ca1f712a77fbe31b954d7e8dee4c9b16ce347b96-ol8_aarch64_appstream
mod_md-2.0.8-8.module+el8.9.0+90011+2f9c6a23.src.rpmb87cd8c00082bf38a8aefb4fbac1eab758639da7e4dfe2387c661fb396a928c0-ol8_aarch64_appstream
mod_http2-1.15.7-10.module+el8.10.0+90652+bef864ba.4.aarch64.rpma8905b42332ca9b0038fc5d8a0e278495633a9fa1952e9f3099ac8e81d5fa7bc-ol8_aarch64_appstream
mod_md-2.0.8-8.module+el8.9.0+90011+2f9c6a23.aarch64.rpm09a6be461741ad2673d307ce619821ea92b3acadfc247ab13d17267c1c6011a6-ol8_aarch64_appstream
Oracle Linux 8 (x86_64) mod_http2-1.15.7-10.module+el8.10.0+90652+bef864ba.4.src.rpmb5447e310ce463e53bdf76d4ca1f712a77fbe31b954d7e8dee4c9b16ce347b96-ol8_x86_64_appstream
mod_md-2.0.8-8.module+el8.9.0+90011+2f9c6a23.src.rpmb87cd8c00082bf38a8aefb4fbac1eab758639da7e4dfe2387c661fb396a928c0-ol8_x86_64_appstream
mod_http2-1.15.7-10.module+el8.10.0+90652+bef864ba.4.x86_64.rpm65e56ad2dcda84643ba43f0141c76732c518331ac718f75c072835b21121fd5a-ol8_x86_64_appstream
mod_md-2.0.8-8.module+el8.9.0+90011+2f9c6a23.x86_64.rpm48e6e9c15ca6394c944f472135dd176c00267760d8f627ddb37e95407ebacbbb-ol8_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete