ELSA-2026-60004-0

ELSA-2026-60004-0 - httpd security update

Type:SECURITY
Impact:LOW
Release Date:2026-08-26

Description


[2.4.63-13.0.1.el10_2.6]
- Replace index.html with Oracle's index page oracle_index.html.

[2.4.63-13.6]
- Resolves: RHEL-190812 - httpd: Apache HTTP Server: Arbitrary code execution
or denial of service via use-after-free in mod_ldap per-directory
configuration (CVE-2026-29167)

[2.4.63-13.5]
- Resolves: RHEL-192750 - mod_proxy_html regression in CVE-2026-34355 fix

[2.4.63-13.4]
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for
CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
CVE-2026-24072, CVE-2026-33006, CVE-2026-43951

[2.4.63-13.1]
- Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)


Related CVEs


CVE-2026-29167

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) httpd-2.4.63-13.0.1.el10_2.6.src.rpm7678fb042cde9a00df6379f64cf92a7e4f06df09a033e926533a1f7db96fce6f-ol10_aarch64_appstream
httpd-2.4.63-13.0.1.el10_2.6.aarch64.rpm641fec0c9642e4302823a5f174ccb9332db49ea029182b928789da49f65be31e-ol10_aarch64_appstream
httpd-core-2.4.63-13.0.1.el10_2.6.aarch64.rpm6c12b39ba6a8b4f2998db1e8d40056e1cad1e00545dac5421d416991648be533-ol10_aarch64_appstream
httpd-devel-2.4.63-13.0.1.el10_2.6.aarch64.rpm8b4ccebc7d583fa5deadc0a926614c0aaa7aa1f51fed22b9812d1276f1631ea5-ol10_aarch64_appstream
httpd-filesystem-2.4.63-13.0.1.el10_2.6.noarch.rpm194758543737abd8b4c6442033bda03da70920b8b0fa512ba47d051176619889-ol10_aarch64_appstream
httpd-manual-2.4.63-13.0.1.el10_2.6.noarch.rpm5fb858ba3b7ddf467fbe45735cb5928a2f0c400ed27d6212e4024aab85bc1c5e-ol10_aarch64_appstream
httpd-tools-2.4.63-13.0.1.el10_2.6.aarch64.rpm8ff439ecf817d5f2da657e0d1b17ff970ab36582b4eb22dda4dc466d30f46eb9-ol10_aarch64_appstream
mod_ldap-2.4.63-13.0.1.el10_2.6.aarch64.rpmc9d121bfca02c75a2bcd869fa9193ad8b20caaac78d00b5f18eec5fe7cb7aace-ol10_aarch64_appstream
mod_lua-2.4.63-13.0.1.el10_2.6.aarch64.rpmc0fbe3415772bf5f47128227f1d543aeb7d5bec77b0c6c8e40213308094ab97f-ol10_aarch64_appstream
mod_proxy_html-2.4.63-13.0.1.el10_2.6.aarch64.rpm585b1afa7e18f9402bb325d98f512f7b2aec0c1715fff78fba5dfe26d377b034-ol10_aarch64_appstream
mod_session-2.4.63-13.0.1.el10_2.6.aarch64.rpm006a03e2ede688c70c0f62ee021df92d8097320ef1699bf8a6024a74dec4acd0-ol10_aarch64_appstream
mod_ssl-2.4.63-13.0.1.el10_2.6.aarch64.rpmf44b205b19263049a23f3a7357370d4b8b3fdc693a8807348eb5c5a51582edbd-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) httpd-2.4.63-13.0.1.el10_2.6.src.rpm7678fb042cde9a00df6379f64cf92a7e4f06df09a033e926533a1f7db96fce6f-ol10_x86_64_appstream
httpd-2.4.63-13.0.1.el10_2.6.x86_64.rpm9ca6f24faadcf0e6cdd62e8de1dfc8760abfb036eab2acd0dcec0d14e64ea684-ol10_x86_64_appstream
httpd-core-2.4.63-13.0.1.el10_2.6.x86_64.rpm966e31ac57691907afc035cf582866ee452711303a59e389239602f1c1f2909a-ol10_x86_64_appstream
httpd-devel-2.4.63-13.0.1.el10_2.6.x86_64.rpmb6992ab9f6a04ec3afa35834050903865a9f2f293e3c20806c40ad73bf18dcc4-ol10_x86_64_appstream
httpd-filesystem-2.4.63-13.0.1.el10_2.6.noarch.rpm194758543737abd8b4c6442033bda03da70920b8b0fa512ba47d051176619889-ol10_x86_64_appstream
httpd-manual-2.4.63-13.0.1.el10_2.6.noarch.rpm5fb858ba3b7ddf467fbe45735cb5928a2f0c400ed27d6212e4024aab85bc1c5e-ol10_x86_64_appstream
httpd-tools-2.4.63-13.0.1.el10_2.6.x86_64.rpmd12dcf5629df387b774876b20bd00c1d72dd4587bf369728d3f90e13d1a8266d-ol10_x86_64_appstream
mod_ldap-2.4.63-13.0.1.el10_2.6.x86_64.rpm59641e7eadfaba24feb75a5084fdabe3c7397bdfc0048bb485cddfcfb4570925-ol10_x86_64_appstream
mod_lua-2.4.63-13.0.1.el10_2.6.x86_64.rpm46bd6f76daa1133ca547780a38b239009703182e6f3fbd355f056878ff6e7e93-ol10_x86_64_appstream
mod_proxy_html-2.4.63-13.0.1.el10_2.6.x86_64.rpm25652b597ff33f821263bce68d2a25467bb9cc4f8c3d8e988bcaf9a29515563a-ol10_x86_64_appstream
mod_session-2.4.63-13.0.1.el10_2.6.x86_64.rpmaf3bc2575b56aaae3dfbd07af8ad868d17da5adf8ea2cb385021ab2bdd849ecf-ol10_x86_64_appstream
mod_ssl-2.4.63-13.0.1.el10_2.6.x86_64.rpm23e5ddfda85bc8b08a06d9e5ca8a8a12eaaa25df8aa5938b822936d1a31e5a93-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete