Bug#1135737: marked as done (apache2: CVE-2026-23918 CVE-2026-24072 CVE-2026-29169 CVE-2026-33006 CVE-2026-33007 CVE-2026-33523 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059)
"Debian Bug Tracking System" <[email protected]> Tue, 05 May 2026 21:35:02 +0000
| Newsgroups | gmane.linux.debian.devel.apache |
|---|---|
| Message-ID | <handler.1135737.D1135737.17780167402687503.ackdone__2946.75484053499$1778016935$gmane$org@bugs.debian.org> |
This is a multi-part message in MIME format... ------------=_1778016902-2689015-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Tue, 05 May 2026 21:32:17 +0000 with message-id <[email protected]> and subject line Bug#1135737: fixed in apache2 2.4.67-1~deb12u1 has caused the Debian Bug report #1135737, regarding apache2: CVE-2026-23918 CVE-2026-24072 CVE-2026-29169 CVE-2026-33= 006 CVE-2026-33007 CVE-2026-33523 CVE-2026-33857 CVE-2026-34032 CVE-2026-34= 059 to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 1135737: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D1135737 Debian Bug Tracking System Contact [email protected] with problems ------------=_1778016902-2689015-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 5 May 2026 11:29:36 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-9.9 required=4.0 tests=BAYES_00,FOURLA,FROMDEVELOPER, NO_RELAYS,XMAILER_REPORTBUG autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 54; hammy, 150; neutral, 114; spammy, 0. spammytokens: hammytokens:0.000-+--H*F:U*carnil, 0.000-+--XDebbugsCc, 0.000-+--X-Debbugs-Cc, 0.000-+--trixie, 0.000-+--bookworm Return-path: <[email protected]> Received: via submission by buxtehude.debian.org with esmtp (Exim 4.96) (envelope-from <[email protected]>) id 1wKDy2-00A4Ql-2x for [email protected]; Tue, 05 May 2026 11:29:36 +0000 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: Salvatore Bonaccorso <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: apache2: CVE-2026-23918 CVE-2026-24072 CVE-2026-29169 CVE-2026-33006 CVE-2026-33007 CVE-2026-33523 CVE-2026-33857 CVE-2026-34032 CVE-2026-34059 Message-ID: <[email protected]> X-Mailer: reportbug 13.2.0 Date: Tue, 05 May 2026 13:29:27 +0200 Delivered-To: [email protected] Source: apache2 Version: 2.4.66-8 Severity: grave Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Control: found -1 2.4.66-1~deb13u2 Control: found -1 2.4.66-1~deb13u1 Control: found -1 2.4.66-1~deb12u2 Control: found -1 2.4.66-1~deb12u1 Hi, The following vulnerabilities were published for apache2. I'm making this RC because of CVE-2026-23918. On 16th may there is a point release for both bookworm and trixie. We were pondering about either a DSA or point release update. Assuming the SRM do not have problem with it, uploading the fixed version to unstable soonish, followed with pu updates to get the updae exposed to public would be nice. CVE-2026-23918[0]: | Double Free and possible RCE vulnerability in Apache HTTP Server | with the HTTP/2 protocol. This issue affects Apache HTTP Server: | 2.4.66. Users are recommended to upgrade to version 2.4.67, which | fixes the issue. CVE-2026-24072[1]: | An escalation of privilege bug in various modules in Apache HTTP | 2.4.66 and earlier allows local .htaccess authors to read files with | the privileges of the httpd user. Users are recommended to upgrade | to version 2.4.67, which fixes this issue. CVE-2026-29169[2]: | A NULL pointer dereference in mod_dav_lock in Apache HTTP Server | 2.4.66 and earlier may allow an attacker to crash the server with a | malicious request.mod_dav_lock is not used internally by mod_dav or | mod_dav_fs. The only known use-case for mod_dav_lock was | mod_dav_svn from Apache Subversion earlier than version 1.2.0. | Users are recommended to upgrade to version 2.4.66, which fixes this | issue, or remove mod_dav_lock. CVE-2026-33006[3]: | A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 | allows a bypass of Digest authentication by a remote attacker. | Users are recommended to upgrade to version 2.4.67, which fixes this | issue. CVE-2026-33007[4]: | A NULL pointer dereference in the mod_authn_socache in Apache HTTP | Server 2.4.66 and earlier allows an unauthenticated remote user to | crash a child process in a caching forward proxy configuration. | Users are recommended to upgrade to version 2.4.67, which fixes this | issue. CVE-2026-33523[5]: | HTTP response splitting vulnerability in multiple Apache HTTP Server | modules with untrusted or compromised backend servers. This issue | affects Apache HTTP Server: from through 2.4.66. Users are | recommended to upgrade to version 2.4.67, which fixes the issue. CVE-2026-33857[6]: | Out-of-bounds Read vulnerability in mod_proxy_ajp of Apache HTTP | Server. This issue affects Apache HTTP Server: through 2.4.66. | Users are recommended to upgrade to version 2.4.67, which fixes the | issue. CVE-2026-34032[7]: | Improper Null Termination, Out-of-bounds Read vulnerability in | Apache HTTP Server. This issue affects Apache HTTP Server: through | 2.4.66. Users are recommended to upgrade to version 2.4.67, which | fixes the issue. CVE-2026-34059[8]: | Buffer Over-read vulnerability in Apache HTTP Server. This issue | affects Apache HTTP Server: through 2.4.66. Users are recommended | to upgrade to version 2.4.67, which fixes the issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-23918 https://www.cve.org/CVERecord?id=CVE-2026-23918 [1] https://security-tracker.debian.org/tracker/CVE-2026-24072 https://www.cve.org/CVERecord?id=CVE-2026-24072 [2] https://security-tracker.debian.org/tracker/CVE-2026-29169 https://www.cve.org/CVERecord?id=CVE-2026-29169 [3] https://security-tracker.debian.org/tracker/CVE-2026-33006 https://www.cve.org/CVERecord?id=CVE-2026-33006 [4] https://security-tracker.debian.org/tracker/CVE-2026-33007 https://www.cve.org/CVERecord?id=CVE-2026-33007 [5] https://security-tracker.debian.org/tracker/CVE-2026-33523 https://www.cve.org/CVERecord?id=CVE-2026-33523 [6] https://security-tracker.debian.org/tracker/CVE-2026-33857 https://www.cve.org/CVERecord?id=CVE-2026-33857 [7] https://security-tracker.debian.org/tracker/CVE-2026-34032 https://www.cve.org/CVERecord?id=CVE-2026-34032 [8] https://security-tracker.debian.org/tracker/CVE-2026-34059 https://www.cve.org/CVERecord?id=CVE-2026-34059 Regards, Salvatore ------------=_1778016902-2689015-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 1135737-close) by bugs.debian.org; 5 May 2026 21:32:20 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-113.1 required=4.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,HAS_BUG_NUMBER, MD5_SHA1_SUM,PGPSIGNATURE,RCVD_IN_DNSWL_MED,SPF_HELO_PASS,SPF_PASS, USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 81; hammy, 150; neutral, 176; spammy, 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK, 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo Return-path: <[email protected]> Received: from mitropoulos.debian.org ([2001:648:2ffc:deb:216:61ff:fe9d:958d]:60152) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wKNNM-00BH8e-0T for [email protected]; Tue, 05 May 2026 21:32:20 +0000 Received: via submission from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified) by mitropoulos.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wKNNK-004VVb-0w for [email protected]; Tue, 05 May 2026 21:32:18 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type: Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID :Content-Description:In-Reply-To:References; bh=+sTy2SuxcdSX2avtJa10BEegTPj6NDDatZCJQmXJ3qo=; b=afYaM0EMOMi4p9JT/c8BhHtEsx DJu854xoQSMyysD+ifO8RcMCMtAxNSwqChMhWyRDVL8ajfYbzAERIfm5gTXO4eqHjuMsI6oQqwiBb F3B7SFZ46DoF/kU5AfJ6zAiTf+oSrc98J2yeBAcAY2XyRC21TdDExZprDp5r5dRP14RpiFrJIbUNI 5YQsV8m2mZL7zKNiL6zfrRVMW0WRWmlG8GnjXpLO8D7ldS2rqU7OvVr62EDSWH0feVNdY/N6ywlgx p9NP9kklsiaBuq9SeGpIBiJB08jafji6Kif1cxH/3HgYzPhbmLZt9u9uoEK+DkDJMbhD/ucoJybWh Y7/RVakw==; Received: from dak by fasolo.debian.org with local (Exim 4.98.2) (envelope-from <[email protected]>) id 1wKNNJ-00000005Pmi-0PVY; Tue, 05 May 2026 21:32:17 +0000 From: Debian FTP Masters <[email protected]> Reply-To: Xavier Guimard <[email protected]> To: [email protected] X-DAK: dak process-policy X-Debian: DAK X-Debian-Package: apache2 Debian: DAK Debian-Changes: apache2_2.4.67-1~deb12u1_sourceonly.changes Debian-Source: apache2 Debian-Version: 2.4.67-1~deb12u1 Debian-Architecture: source Debian-Suite: oldstable-proposed-updates Debian-Archive-Action: accept MIME-Version: 1.0 Subject: Bug#1135737: fixed in apache2 2.4.67-1~deb12u1 Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============6001432782188246477==" Message-Id: <[email protected]> Date: Tue, 05 May 2026 21:32:17 +0000 --===============6001432782188246477== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Source: apache2 Source-Version: 2.4.67-1~deb12u1 Done: Xavier Guimard <[email protected]> We believe that the bug you reported is fixed in the latest version of apache2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Xavier Guimard <[email protected]> (supplier of updated apache2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 05 May 2026 14:27:00 +0200 Source: apache2 Architecture: source Version: 2.4.67-1~deb12u1 Distribution: bookworm Urgency: medium Maintainer: Debian Apache Maintainers <[email protected]> Changed-By: Xavier Guimard <[email protected]> Closes: 1135737 Changes: apache2 (2.4.67-1~deb12u1) bookworm; urgency=3Dmedium . * New upstream release (Closes: #1135737, CVE-2026-23918, CVE-2026-24072, CVE-2026-29169, CVE-2026-33006, CVE-2026-33007, CVE-2026-33523, CVE-2026-33857, CVE-2026-34032, CVE-2026-34059) * Refresh patches Checksums-Sha1:=20 f4666f23be9114c7d724c649ea9e5345f12aaa07 3559 apache2_2.4.67-1~deb12u1.dsc 46e72f3395f75d49d6c8ab20c31521bf1a3d8107 9714011 apache2_2.4.67.orig.tar.gz 837c2618ed0b131cdab25466f45bceb7fb73c291 870 apache2_2.4.67.orig.tar.gz.asc 987b704d8affdb266ebb2393f2788525e6b94e16 823864 apache2_2.4.67-1~deb12u1.deb= ian.tar.xz Checksums-Sha256:=20 8671621ea3184367ea05f48659a0442647f728c9f891ec518e9965d29c84aa8a 3559 apache= 2_2.4.67-1~deb12u1.dsc 10a578d199c3930250534fac629995f34ef7571709a7c88c45239e1fdc88cf77 9714011 apa= che2_2.4.67.orig.tar.gz d8a6e18c2f892aa901121d14852717bddf42e430b0f48f853a4effce7b89f348 870 apache2= _2.4.67.orig.tar.gz.asc da400801de441cbb0003497908f0dd3075d4a8e469dd3d73b24d84ebb906ce7c 823864 apac= he2_2.4.67-1~deb12u1.debian.tar.xz Files:=20 ae2dbae52219bd90d0c96014236e689a 3559 httpd optional apache2_2.4.67-1~deb12u= 1.dsc cf51fc1963b35360240f4225c2921d4b 9714011 httpd optional apache2_2.4.67.orig.= tar.gz 8831f0957bcf06bb810d7def20d5d790 870 httpd optional apache2_2.4.67.orig.tar.= gz.asc 47d85a430b2ba621e941fb17e33f9012 823864 httpd optional apache2_2.4.67-1~deb1= 2u1.debian.tar.xz -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEAN/li4tVV3nRAF7J9tdMp8mZ7ukFAmn6I84ACgkQ9tdMp8mZ 7ukLhRAAmom+PKDmDg53qrSx+TVXGOYnE+RRiTQtNbn2g5U9IWEn03Z6nQICqOno hzoUYl9l1PZCuNUBz6zuztE0c6c1BBqJ6Ut7PapQ45SGG48AQryoFs+gU1A5Mywm MxKoiW6n22cTtSZVetZqMSlPKGjbIWRICCRjCI40XNf3eZLdYkGXC4/fp31LUOdP NG/pIIFz+buJvbiokmkttmBvCVKpoBdoMHrFguiFM6IfgwoiU3P/8ESnD/bt/7qT qNMKYYqEpkAFEkxr3ag6QEdgvV5ScgVxPI+k5lphKgPGDze2LNi9ToDUscHNM3FN c2lI/DEKSizCN++bdPxnJmTbVxjlnQprCk97cny9pT7bVoqEfFCYn9xhziZjTJbU JUWXbBHgzJDI0pQd8KRT+i4PDXHJOQH5mwv7ugJ2CYT1EzlDaFOLgprVrIR5pj3L bMdV5YtzYw8xb5HpuVjWZD4q8GQux7V8rKeP/+CkmbZZGbqqi999xs3J4S2FCKSZ zlV7419S/kjmUZ05SPjkPeDFWUKkhKWqooVdah8QVvbHbQu91VJh6H/ClHT9jsUl DfEzY8KjxK/b0ivDplklHuFnDLhdzbhKaFP0nzfprVLkACwb+gTbxV8/1zhQETqn WCaB/g0VkcCunKjxF0D2C4qUSh2/5wpZiLbABcDIU89jCi1RDdQ=3D =3DNogZ -----END PGP SIGNATURE----- --===============6001432782188246477== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCafph4QAKCRCb9qggYcy5 IfgvAPsEOtGViT+AWZPw5/VWZO9tyly9ALwm8nrH0YI7WNEVsQEAzeTEonecn6w3 QtEsGIhCXn4pvGyAI/CfJ3RxeK6XpAc= =LGcD -----END PGP SIGNATURE----- --===============6001432782188246477==-- ------------=_1778016902-2689015-0--