|
|
Log in / Subscribe / Register

Ubuntu alert USN-8396-1 (apache2)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8396-1] Apache HTTP Server vulnerabilities
Date:  Fri, 12 Jun 2026 05:40:21 +0000
Message-ID:  <E1wXucv-00034R-2T@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8396-1 June 08, 2026 apache2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: It was discovered that the Apache HTTP Server mod_rewrite module incorrectly handled certain privileges. A local attacker could possibly use this issue to obtain sensitive information. (CVE-2026-24072) Andrew Lacambra, Elhanan Haenel, Tianshuo Han, and Tristan Madani discovered that the Apache HTTP Server mod_proxy_ajp module incorrectly handled certain AJP server messages. An attacker in control of a backend AJP server could use this issue to cause Apache HTTP Server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-28780) Pavel Kohout discovered that the Apache HTTP Server incorrectly handled certain memory operations in mod_dav_lock. A remote attacker could possibly use this issue to cause Apache HTTP Server to crash, resulting in a denial of service. (CVE-2026-29169) Elhanan Haenel discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_proxy_ajp. A remote attacker could use this issue to cause Apache HTTP Server to crash, resulting in a denial of service, or possibly obtain sensitive information. (CVE-2026-34059) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS apache2 2.4.41-4ubuntu3.23+esm4 Available with Ubuntu Pro apache2-bin 2.4.41-4ubuntu3.23+esm4 Available with Ubuntu Pro apache2-dev 2.4.41-4ubuntu3.23+esm4 Available with Ubuntu Pro apache2-ssl-dev 2.4.41-4ubuntu3.23+esm4 Available with Ubuntu Pro apache2-utils 2.4.41-4ubuntu3.23+esm4 Available with Ubuntu Pro libapache2-mod-md 2.4.41-4ubuntu3.23+esm4 Available with Ubuntu Pro Ubuntu 18.04 LTS apache2 2.4.29-1ubuntu4.27+esm9 Available with Ubuntu Pro apache2-bin 2.4.29-1ubuntu4.27+esm9 Available with Ubuntu Pro apache2-dev 2.4.29-1ubuntu4.27+esm9 Available with Ubuntu Pro apache2-ssl-dev 2.4.29-1ubuntu4.27+esm9 Available with Ubuntu Pro apache2-utils 2.4.29-1ubuntu4.27+esm9 Available with Ubuntu Pro Ubuntu 16.04 LTS apache2 2.4.18-2ubuntu3.17+esm18 Available with Ubuntu Pro apache2-bin 2.4.18-2ubuntu3.17+esm18 Available with Ubuntu Pro apache2-data 2.4.18-2ubuntu3.17+esm18 Available with Ubuntu Pro apache2-dev 2.4.18-2ubuntu3.17+esm18 Available with Ubuntu Pro apache2-utils 2.4.18-2ubuntu3.17+esm18 Available with Ubuntu Pro Ubuntu 14.04 LTS apache2 2.4.7-1ubuntu4.22+esm13 Available with Ubuntu Pro apache2-bin 2.4.7-1ubuntu4.22+esm13 Available with Ubuntu Pro apache2-dev 2.4.7-1ubuntu4.22+esm13 Available with Ubuntu Pro apache2-utils 2.4.7-1ubuntu4.22+esm13 Available with Ubuntu Pro apache2.2-bin 2.4.7-1ubuntu4.22+esm13 Available with Ubuntu Pro After a standard system update you need to restart apache2 to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8396-1 CVE-2026-24072, CVE-2026-28780, CVE-2026-29169, CVE-2026-34059


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmoo828ACgkQcpJm3tlz hgEKDxAAuXBu9asr9ezVdiDrhjZcCFRLuv1EiiSa8gRD0lf7FlX8qFDGA8Qw4j1J l1s9DNijcN+e4N+6/uKZ1Jh5Uc5X20VME7caTT4x/QMGYS+QLSlkqXb0qYaf3Hih JtrMFpx7cBk7md1sLMb+sT6CkFcCI1gn6WC5VnyCy4p0q8V87oYDDpfuKyg2m5MO Q+ImZT/+VnNghS4NZCxFx+iKKP8XDE7NqupXPW1MhHXIeqCDKyML6bYR3MtuvKN8 GgYHE7qEYkGr0IQVeZelhX4Ami5SJKwhAPSJmdmehyjgyjwV48Lzrs1fQtrth0xY 8cqtQUJJ342LODRU38LdgIz86VUWhUn4KGwCcte/vTT9RtrfjT8qFT2Fxmnf+hKM 6x8t+MfZg2Rfk8VJsD48RYxbuMAFT1bmGoZDiiJrZ2/++ZjklaBmhVaeuFgIecXb YqQfyKX6z1Od12xZPFkKNEjoKnuTtxEtTv4hBnMRIXINQgY41Or6MN23/5k3ZufJ +ABhJ80zUAFVuxkVxeSXelqL4mNfeB/VDS1BoBnH4/CIr/k9+AlXP2HKxwaz0zlI 5YY+f1fgDNMCJtjhc/UMec7WkpCKl55tRjo/fQJUD7REQ1ncylF4K2D65/WULPOE x65XnUF0uE6zm6wEIfcDIfna8UzY2iTcRJs3+zB8Sv7vVhW2SJY= =IKrl -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds