Ubuntu alert USN-8338-1 (apache2)
| From: | noreply+usn-bot@canonical.com | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8338-1] Apache HTTP Server vulnerabilities | |
| Date: | Thu, 28 May 2026 17:38:05 +0000 | |
| Message-ID: | <E1wSegH-00071j-7T@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-8338-1 May 28, 2026 apache2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: It was discovered that Apache HTTP Server incorrectly handled certain response headers. An attacker could possibly use this issue to perform HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2023-38709) Will Dormann and David Warren discovered that Apache HTTP Server's HTTP/2 implementation did not properly reclaim memory when streams were reset by clients. A remote attacker could possibly use this issue to cause Apache HTTP Server to consume resources, leading to a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2023-45802) Keran Mu and Jianjun Chen discovered that Apache HTTP Server incorrectly handled certain response headers. An attacker could possibly use this issue to perform HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-24795) Orange Tsai discovered that Apache HTTP Server mod_proxy incorrectly handled URL encoding. A remote attacker could possibly use this issue to bypass authentication via crafted requests. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-38473) Orange Tsai discovered that Apache HTTP Server could be caused to perform server-side request forgery (SSRF) via malicious backend response headers. A remote attacker could possibly use this issue to conduct SSRF attacks or disclose sensitive information. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38476) Orange Tsai discovered that Apache HTTP Server mod_proxy did not properly handle certain null pointer conditions. A remote attacker could possibly use this issue to cause Apache HTTP Server to crash, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-38477) Orange Tsai discovered that Apache HTTP Server mod_rewrite could be made to perform server-side request forgery (SSRF) via unsafe RewriteRules. A remote attacker could possibly use this issue to conduct SSRF attacks. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-39573) It was discovered that Apache HTTP Server incorrectly handled certain response headers. An attacker could possibly use this issue to perform HTTP response splitting attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-42516) It was discovered that Apache HTTP Server could be caused to perform server-side request forgery (SSRF) via mod_headers modifying Content-Type headers. A remote attacker could possibly use this issue to conduct SSRF attacks. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-43204) John Runyon discovered that Apache HTTP Server mod_ssl did not properly escape user-supplied data before writing log entries. A remote attacker could possibly use this issue to insert escape sequences into log files. This issue only affected Ubuntu 14.04 LTS. (CVE-2024-47252) Robert Merget discovered that Apache HTTP Server with SSLEngine optional was vulnerable to HTTP desynchronisation attacks. An attacker in a privileged network position could possibly use this issue to hijack HTTP sessions. This issue only affected Ubuntu 14.04 LTS. (CVE-2025-49812) It was discovered that Apache HTTP Server mod_md had an integer overflow in the ACME certificate renewal backoff timer. An attacker could possibly use this issue to cause excessive certificate renewal requests. This issue only affected Ubuntu 20.04 LTS. (CVE-2025-55753) Anthony Parfenov discovered that Apache HTTP Server with SSI enabled and mod_cgid passed shell-escaped query strings to #exec cmd directives. A remote attacker could possibly use this issue to perform command injection. (CVE-2025-58098) Mattias Åsander discovered that Apache HTTP Server incorrectly gave precedence to environment variables from HTTP headers over server-calculated CGI variables. A remote attacker could possibly use this issue to influence the environment of CGI programs. (CVE-2025-65082) Mattias Åsander discovered that Apache HTTP Server mod_userdir with suexec could be caused to run CGI scripts under an unexpected user ID via RequestHeader directives in .htaccess files. An attacker with .htaccess write access could possibly use this issue to bypass suexec user restrictions. (CVE-2025-66200) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS apache2 2.4.41-4ubuntu3.23+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS apache2 2.4.29-1ubuntu4.27+esm7 Available with Ubuntu Pro Ubuntu 16.04 LTS apache2 2.4.18-2ubuntu3.17+esm17 Available with Ubuntu Pro Ubuntu 14.04 LTS apache2 2.4.7-1ubuntu4.22+esm12 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8338-1 CVE-2023-38709, CVE-2023-45802, CVE-2024-24795, CVE-2024-38473, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573, CVE-2024-42516, CVE-2024-43204, CVE-2024-47252, CVE-2025-49812, CVE-2025-55753, CVE-2025-58098, CVE-2025-65082, CVE-2025-66200
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoYfV0ACgkQcpJm3tlz hgEcphAAyaCQm9gfm0q7DMQVJ9uAP7pwyweVzb7mOaGs4rOiS1x+GYpXXFFdLaZY se0ow+7dIwvrXhDuobBz0rRDwPm21g1+X/ZVywv3DqI1qUAJgU5KZbUsn+HRYa3a 76yp3sUAlcnVOOVLRvQx5FHL4Z5/cMxSPXi8ngAmw9fL/xMEBz79/ojWnxZDxBdn 4WGI7Bp+M/kTClRDe+VgFdniQcIgzWBU5zo/xmOmviFcrzYXSZSkRNnlYf+avt4d rQMTlQktPDqxkLXMpTyY54ynF5jci6m3nqHJHf0B2EZ60aDCfMgnaGZwkfs/FunU gIlXxHYfFk0vK+u1XmlrY4ozA8LXhGwqOt+ukCqOMwfAJUnOchPMBJB6b0xstW5x jg+zx6h5jwZmRAd6ziAW0w3eHeA2FA/bbwwpaonbR/A2NlMQI5wiwF3kJ6OW5JlT vtzFdCGxrQyVK6qM9aZ7xhm9zUs27P8a2Wo1eSBpdYDXkall8KUmzfDuss2cnQGv JIBSYIT6SuaXUk++DPv9gbCwUvItXNTF2zmCzHSJ1aKtd85K7bcYmS/JvqZuUN0d RpmpXEW5nrgWVXK1fTfZOwk/P3gD4oQToSsuY9tEByJAv3HGUGL7MDOmGbLWlwSY KRvKskTnrTL3zllE+jCvJSHd8NrzAHhBfgfT12jtL7DR8kfM4HM= =NANs -----END PGP SIGNATURE-----
