ELSA-2026-59347

ELSA-2026-59347 - httpd security update

Type:SECURITY
Impact:LOW
Release Date:2026-08-25

Description


[2.4.62-13.0.1.el9_8.6]
- Replace index.html with Oracle's index page oracle_index.html.

[2.4.62-13.6]
- Resolves: RHEL-190807 - httpd: use-after-free in mod_ldap
uldap_connection_find via per-directory client cert list
(CVE-2026-29167)

[2.4.62-13.5]
- Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix

[2.4.62-13.4]
- Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-182578 - httpd: incomplete fix
for CVE-2023-38709 (CVE-2024-42516)
- Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951,
CVE-2026-44119, CVE-2026-44186

[2.4.62-13.3]
- Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling
vulnerability (CVE-2026-34355)
- Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery
(CVE-2026-29169)
- Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto
(CVE-2026-42536)
- Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement
bug in mod_ssl (CVE-2026-44185)

[2.4.62-13.2]
- Resolves: RHEL-184312 - httpd: ap_regname restrict to reasonable captures
(CVE-2026-44631)

[2.4.62-13.1]
- Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)


Related CVEs


CVE-2026-29167

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) httpd-2.4.62-13.0.1.el9_8.6.src.rpm01c512a08f9f8e041c11d03106f39c734bb6858037c72dba47b242efd5fdd197-ol9_aarch64_appstream
httpd-2.4.62-13.0.1.el9_8.6.aarch64.rpma3e6f50ab10278d29eeeff0893701c70bdfd5709a6735887182c97fa09cfcab3-ol9_aarch64_appstream
httpd-core-2.4.62-13.0.1.el9_8.6.aarch64.rpm393701bb8f2be8d29810485a0a9592b226bd52f6a0eb90ae123e76950cdd738a-ol9_aarch64_appstream
httpd-devel-2.4.62-13.0.1.el9_8.6.aarch64.rpmd388725ff4b305873fd1b27875db27215da5b4c40b873c112a3d0ab0e1b028c6-ol9_aarch64_appstream
httpd-filesystem-2.4.62-13.0.1.el9_8.6.noarch.rpm6e5bc95f856f9098dab71e446e46f5f759845c3a246084605a9af53d8edf4ba6-ol9_aarch64_appstream
httpd-manual-2.4.62-13.0.1.el9_8.6.noarch.rpm827830b5b0a4552c58bca8baefdbf0e30e240c8f3dcb45a09fde31dabffe3045-ol9_aarch64_appstream
httpd-tools-2.4.62-13.0.1.el9_8.6.aarch64.rpm990a259ed90710015ce26d1b348fb00b7b42e078e6f68efeea2420080539c30a-ol9_aarch64_appstream
mod_ldap-2.4.62-13.0.1.el9_8.6.aarch64.rpm3b12a164edd0f9acd20aa255b78f9868764738e84ded65676bc89575085c44ea-ol9_aarch64_appstream
mod_lua-2.4.62-13.0.1.el9_8.6.aarch64.rpmbf966e780054e78db178d3deee0dbf81fe9dca75becc053b95b15c6148500499-ol9_aarch64_appstream
mod_proxy_html-2.4.62-13.0.1.el9_8.6.aarch64.rpm39637a09ec648339c44e0883502ae95741739df7227d48750fa484555af4a5c9-ol9_aarch64_appstream
mod_session-2.4.62-13.0.1.el9_8.6.aarch64.rpmfb98a7f9d6665e4c04c51cdc21438baa009c21cb3c4558ee53bba796ebc3a0fb-ol9_aarch64_appstream
mod_ssl-2.4.62-13.0.1.el9_8.6.aarch64.rpmccc3ba171a0941e45bb2ec26668cbf3b5d8b7c59cf1fd6006c01e33cdd7371ad-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) httpd-2.4.62-13.0.1.el9_8.6.src.rpm01c512a08f9f8e041c11d03106f39c734bb6858037c72dba47b242efd5fdd197-ol9_x86_64_appstream
httpd-2.4.62-13.0.1.el9_8.6.x86_64.rpm56fa5356b6930d3163f7969acdd431d103b87642a8138e93a75d9864dbcae4d7-ol9_x86_64_appstream
httpd-core-2.4.62-13.0.1.el9_8.6.x86_64.rpmd39cf6e3904f4b2d947ef394f85ffef3b893e3f99deef8ff70cfec201d3549fc-ol9_x86_64_appstream
httpd-devel-2.4.62-13.0.1.el9_8.6.x86_64.rpm5c9601dd54bc39c4974c4e850ad8fd8fe373676729a5872723b6d228e20a579a-ol9_x86_64_appstream
httpd-filesystem-2.4.62-13.0.1.el9_8.6.noarch.rpm6e5bc95f856f9098dab71e446e46f5f759845c3a246084605a9af53d8edf4ba6-ol9_x86_64_appstream
httpd-manual-2.4.62-13.0.1.el9_8.6.noarch.rpm827830b5b0a4552c58bca8baefdbf0e30e240c8f3dcb45a09fde31dabffe3045-ol9_x86_64_appstream
httpd-tools-2.4.62-13.0.1.el9_8.6.x86_64.rpm5c432c629c8489c28219fe7b9a8fafffee3cdf3595c91f52f4426d66dbe19d8e-ol9_x86_64_appstream
mod_ldap-2.4.62-13.0.1.el9_8.6.x86_64.rpma28737a8cf48eec7e2a3558ce3c4d4b7216d91be21e39e77e1928e3b804d0cee-ol9_x86_64_appstream
mod_lua-2.4.62-13.0.1.el9_8.6.x86_64.rpmea1f442c0684a7a50b3ba89f68458b2f605741e0429279bed491542406fd5704-ol9_x86_64_appstream
mod_proxy_html-2.4.62-13.0.1.el9_8.6.x86_64.rpm410acc8872c7d754a9ab3a5b2efceb6fc4877b05140a0275cc728226bc87b008-ol9_x86_64_appstream
mod_session-2.4.62-13.0.1.el9_8.6.x86_64.rpme157b3ee4478a1e1331e3cc803f79594c08bd3daa3e81aec64145fb2a9d4e831-ol9_x86_64_appstream
mod_ssl-2.4.62-13.0.1.el9_8.6.x86_64.rpm9190f287582b6bc52ecdf150b0a05b289627b65baa4bd964b1b58daeed7d835f-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete