ELSA-2026-41906

ELSA-2026-41906 - httpd security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-07-20

Description


[2.4.62-13.0.1.el9_8.5]
- Replace index.html with Oracle's index page oracle_index.html.

[2.4.62-13.5]
- Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix

[2.4.62-13.4]
- Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-182578 - httpd: incomplete fix
for CVE-2023-38709 (CVE-2024-42516)
- Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951,
CVE-2026-44119, CVE-2026-44186

[2.4.62-13.3]
- Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling
vulnerability (CVE-2026-34355)
- Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery
(CVE-2026-29169)
- Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto
(CVE-2026-42536)
- Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement
bug in mod_ssl (CVE-2026-44185)

[2.4.62-13.2]
- Resolves: RHEL-184312 - httpd: ap_regname restrict to reasonable captures
(CVE-2026-44631)

[2.4.62-13.1]
- Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)


Related CVEs


CVE-2024-42516
CVE-2026-24072
CVE-2026-29169
CVE-2026-33006
CVE-2026-34355
CVE-2026-34356
CVE-2026-42535
CVE-2026-42536
CVE-2026-43951
CVE-2026-44119
CVE-2026-44185
CVE-2026-44186
CVE-2026-44631

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) httpd-2.4.62-13.0.1.el9_8.5.src.rpm69e55fa5091e4b1ba2a505d907a1dd12098c20df7fa67027c8d2ccd99db50783-ol9_aarch64_appstream
httpd-2.4.62-13.0.1.el9_8.5.aarch64.rpm306ff858603058e16c375b051da76ffa97fa254b346c8df47d1c3d167c03e816-ol9_aarch64_appstream
httpd-core-2.4.62-13.0.1.el9_8.5.aarch64.rpma3ce6515bbb209f369a3bcdb20b4101505e5b3fc7247c910e9fed820d3fc2b10-ol9_aarch64_appstream
httpd-devel-2.4.62-13.0.1.el9_8.5.aarch64.rpmfca37d1226aacfeef675e2b855cccab6f44915f223669d70ea05c47c507ab3aa-ol9_aarch64_appstream
httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpmbb8e1f6264e45bf0245fad8f0563b8172cc84682656b6866881c41b34a01a18a-ol9_aarch64_appstream
httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm1c64e1db713a7d42bd1e25f850321fba5e6ce822a71fc600499a17c36e1d3bde-ol9_aarch64_appstream
httpd-tools-2.4.62-13.0.1.el9_8.5.aarch64.rpm524a49f492be1983fae722ac1633ba87dd5980ce84090102ce15ab42baac5a1a-ol9_aarch64_appstream
mod_ldap-2.4.62-13.0.1.el9_8.5.aarch64.rpm6e9c371a46909796e1f4cbbd8f43e9c1697fad438b5a818a8a1c52cb28dc79c5-ol9_aarch64_appstream
mod_lua-2.4.62-13.0.1.el9_8.5.aarch64.rpmc39452be4c710e32cc0fa1941cf4d0e8e22faa2620ed0a031891ed668cf0cbb1-ol9_aarch64_appstream
mod_proxy_html-2.4.62-13.0.1.el9_8.5.aarch64.rpm0cde5ce5d9e2f44320c03ba2b594a89757360dee15389f725e59b829b30fa0ef-ol9_aarch64_appstream
mod_session-2.4.62-13.0.1.el9_8.5.aarch64.rpm042718e4cfcf81ab9116a764994495f928b4cc5d9feeed8df855355f105547dc-ol9_aarch64_appstream
mod_ssl-2.4.62-13.0.1.el9_8.5.aarch64.rpm4a247f0b9e77f4265b000d47e6ee7b8e5412267a18d45900e11d8be133905e1f-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) httpd-2.4.62-13.0.1.el9_8.5.src.rpm69e55fa5091e4b1ba2a505d907a1dd12098c20df7fa67027c8d2ccd99db50783-ol9_x86_64_appstream
httpd-2.4.62-13.0.1.el9_8.5.x86_64.rpm8f5a481f410fd6ebf1ef8e825879e5451560a2ad174ea01d58e388e4ae5871b6-ol9_x86_64_appstream
httpd-core-2.4.62-13.0.1.el9_8.5.x86_64.rpm1a4d41c8e607a072a91c1cd4828ec4e5a3b6824e562d9203c059589ebcff5e84-ol9_x86_64_appstream
httpd-devel-2.4.62-13.0.1.el9_8.5.x86_64.rpm6e5f5f102a65df381a2ce4e39b02cf9c6e734523c642ee0124c4f3c12cf849ef-ol9_x86_64_appstream
httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpmbb8e1f6264e45bf0245fad8f0563b8172cc84682656b6866881c41b34a01a18a-ol9_x86_64_appstream
httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm1c64e1db713a7d42bd1e25f850321fba5e6ce822a71fc600499a17c36e1d3bde-ol9_x86_64_appstream
httpd-tools-2.4.62-13.0.1.el9_8.5.x86_64.rpmac55650205379fc3374dcc472036557039615a514c88358e85d8d08452b4e5d0-ol9_x86_64_appstream
mod_ldap-2.4.62-13.0.1.el9_8.5.x86_64.rpm081c735ef9dc90d863e455ec7dc3ae09affe5ac559da694f4318ce73e37641bb-ol9_x86_64_appstream
mod_lua-2.4.62-13.0.1.el9_8.5.x86_64.rpm0db500634da0f43d94e6c9457d0e0f8fbae01098584f9c7de28343e38d846e8e-ol9_x86_64_appstream
mod_proxy_html-2.4.62-13.0.1.el9_8.5.x86_64.rpmb13cda851588f40ad52d25441d445b1804371058cfa1e941fda1ebf3233e5b37-ol9_x86_64_appstream
mod_session-2.4.62-13.0.1.el9_8.5.x86_64.rpmcc4e04cb59f70370a010487f134caf234e2e64134cb3ddd954d2c86f9e39cceb-ol9_x86_64_appstream
mod_ssl-2.4.62-13.0.1.el9_8.5.x86_64.rpm68628a3fe49a2d5af6cbf113ec6efedeb0de6dee5700ebac06cfa3da737cfdad-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete