[CLSA-2026:1782141828] httpd: Fix of 6 CVEs
Type:
security
Severity:
Important
Release date:
2026-06-22 15:24:08 UTC
Description:
- CVE-2026-43951: mod_headers/mod_mime OOB read in merge_response_headers via multiple Content-Language values - CVE-2026-44119: mod_rewrite/mod_setenvif/mod_proxy_fcgi privilege escalation through expressions in .htaccess - CVE-2026-44185: mod_ssl OCSP outbound request stack buffer over-read with attacker-controlled responder - CVE-2026-44186: mod_proxy_ftp infinite loop via attacker-controlled backend FTP server - CVE-2026-44631: ap_regname heap underflow on crafted regular expressions in /// configuration - CVE-2026-48913: mod_http2 use-after-free when file handles are exhausted on upload requests
Updated packages:
  • httpd-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:8acfabfe7bc4e13725a35b5ba93d1eadee9c75b9266fdd5bb28dd69529456284
  • httpd-devel-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:e52f1c1adc6d91a35632272a5f76982d3aa08d55fe17878b4bedb5d03b1b5d0e
  • httpd-filesystem-2.4.67-1.amzn2.0.1.tuxcare.els3.noarch.rpm
    sha:013f49dbd3752979d0be8f37ae688d1e5bfcfabf9b4464cd23fb924eca6e08bc
  • httpd-manual-2.4.67-1.amzn2.0.1.tuxcare.els3.noarch.rpm
    sha:119665daa4fc37f35f8d00d31187631eb863c7e40e42568eca790abb73e90afe
  • httpd-tools-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:83e166dbe3cc21ebaf337362c9949e3bfb22b5e958b545d6abc53bea9d010d70
  • mod_ldap-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:b6f995bafd543a820a7ddf354f5871c71f593af03707bde45e5d1b5a2da8b2a7
  • mod_md-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:9ff0c065c8d1fc29ddc80c4fc6d398cc76987f64b2e3abdd9812fb791a5794a3
  • mod_proxy_html-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:3b0bcc85ab81d7c87c62e92e631cf0031ab969f23f574134555ae17e29dc93a5
  • mod_session-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:eb9e5be855ec595bb53f8cd8a5a8a35d138addbad8b5bf340be86e4b3e006838
  • mod_ssl-2.4.67-1.amzn2.0.1.tuxcare.els3.x86_64.rpm
    sha:a6231dea9bcd9ff88212173747e2ad595e3289b25c3ae6432ab6cbc33b0cb547
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.