{"id":"CLSA-2026-1778934210","summary":"Fix of 7 CVEs","details":"   * SECURITY UPDATE: off-by-one OOB read in mod_proxy_ajp message getters\n     - debian/patches/CVE-2026-33857.patch: tighten length checks\n       (`\u003e msg-\u003elen` -\u003e `\u003e= msg-\u003elen`) in ajp_msg_get_uint8/16/32 and\n       ajp_msg_peek_uint8/16 in modules/proxy/ajp_msg.c.\n     - CVE-2026-33857\n   * SECURITY UPDATE: heap over-read in mod_proxy_ajp via missing\n     null-termination check in ajp_msg_get_string()\n     - debian/patches/CVE-2026-34032.patch: switch the buffer overflow\n       check to compare against msg-\u003elen and verify the expected null\n       terminator is present before returning the pointer in\n       modules/proxy/ajp_msg.c.\n     - CVE-2026-34032\n   * SECURITY UPDATE: heap over-read and memory disclosure in\n     mod_proxy_ajp ajp_parse_data() via missing minimum message-length\n     validation\n     - debian/patches/CVE-2026-34059.patch: reject AJP data messages\n       whose `msg-\u003elen` is smaller than AJP_HEADER_LEN +\n       AJP_HEADER_SZ_LEN + 1 + 1 before computing expected_len in\n       modules/proxy/ajp_header.c.\n     - CVE-2026-34059\n   * SECURITY UPDATE: local information disclosure via .htaccess /\n     mod_setenvif / ProxyFCGISetEnvIf, where a non-privileged user\n     with .htaccess write access could read files accessible to the\n     httpd service account\n     - debian/patches/CVE-2026-24072.patch: pass\n       AP_EXPR_FLAG_RESTRICTED when parsing ap_expr expressions from\n       htaccess context in modules/mappers/mod_rewrite.c,\n       modules/metadata/mod_setenvif.c, and\n       modules/proxy/mod_proxy_fcgi.c.\n     - CVE-2026-24072\n   * SECURITY UPDATE: timing attack against mod_auth_digest allowing\n     bypass of Digest authentication\n     - debian/patches/CVE-2026-33006.patch: validate nonce and digest\n       lengths earlier and replace the strcmp of the nonce hash with\n       the constant-time apr_crypto_equals (apr-util \u003e= 1.6) in\n       modules/aaa/mod_auth_digest.c; bump APU minimum to 1.6 in\n       configure.in.\n     - CVE-2026-33006\n   * SECURITY UPDATE: NULL pointer dereference in mod_authn_socache\n     crashes the child process in a caching forward proxy setup\n     - debian/patches/CVE-2026-33007.patch: validate the URL before\n       using the cache hash in construct_key() in\n       modules/aaa/mod_authn_socache.c.\n     - CVE-2026-33007\n   * SECURITY UPDATE: HTTP response splitting via newline/control\n     characters in an outgoing status line forwarded from a\n     compromised backend\n     - debian/patches/CVE-2026-33523.patch: reject status reason\n       strings that contain newlines or control characters in\n       modules/http/http_filters.c.\n     - CVE-2026-33523","modified":"2026-06-04T10:04:46.247032335Z","published":"2026-05-16T14:38:58Z","upstream":["CVE-2026-24072","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu20.04els/CLSA-2026-1778934210.html"}],"affected":[{"package":{"name":"apache2","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-bin","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-bin?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-data","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-data?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-dev","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-dev?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-doc","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-doc?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-ssl-dev","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-ssl-dev?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-suexec-custom","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-suexec-custom?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-suexec-pristine","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-suexec-pristine?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"apache2-utils","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/apache2-utils?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"libapache2-mod-md","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libapache2-mod-md?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}},{"package":{"name":"libapache2-mod-proxy-uwsgi","ecosystem":"TuxCare:Ubuntu:20.04","purl":"pkg:deb/tuxcare/libapache2-mod-proxy-uwsgi?distro=ubuntu-20.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.41-4ubuntu3.23+tuxcare.els4"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu20.04els/CLSA-2026-1778934210.json"}}],"schema_version":"1.7.5"}