{"id":"CLSA-2026-1779118679","summary":"Fix of 8 CVEs","details":"   * SECURITY UPDATE: mod_proxy_ajp heap buffer over-read in ajp_msg_get_string\n     - debian/patches/CVE-2026-34032.patch: add buffer checks in\n       modules/proxy/ajp_msg.c.\n     - CVE-2026-34032\n   * SECURITY UPDATE: AJP getter functions off-by-one out-of-bounds reads\n     - debian/patches/CVE-2026-33857.patch: fix length checks in AJP msg_get\n       functions in modules/proxy/ajp_msg.c.\n     - CVE-2026-33857\n   * SECURITY UPDATE: mod_proxy_ajp heap over-read in ajp_parse_data\n     - debian/patches/CVE-2026-34059.patch: fix message length check in\n       modules/proxy/ajp_header.c.\n     - CVE-2026-34059\n   * SECURITY UPDATE: mod_authn_socache crash in caching forward proxy\n     - debian/patches/CVE-2026-33007.patch: validate URL earlier in\n       modules/aaa/mod_authn_socache.c.\n     - CVE-2026-33007\n   * SECURITY UPDATE: HTTP response splitting via malicious backend status line\n     - debian/patches/CVE-2026-33523.patch: scan outgoing status line for\n       newlines and controls in modules/http/http_filters.c.\n     - CVE-2026-33523\n   * SECURITY UPDATE: mod_rewrite elevation of privileges via ap_expr in\n     .htaccess\n     - debian/patches/CVE-2026-24072.patch: use AP_EXPR_FLAG_RESTRICTED in\n       htaccess context in modules/mappers/mod_rewrite.c,\n       modules/metadata/mod_setenvif.c, modules/proxy/mod_proxy_fcgi.c.\n     - CVE-2026-24072\n   * SECURITY UPDATE: mod_auth_digest timing attack allowing Digest auth bypass\n     - debian/patches/CVE-2026-33006.patch: use apr_crypto_equals (constant-\n       time comparison) for nonce hash and digest checks, add VALID_NONCE\n       validation and MD5_DIGEST_LEN length check in get_digest_rec, in\n       modules/aaa/mod_auth_digest.c. Bumps configure.in apr-util requirement\n       to \u003e= 1.6 (bionic ships 1.6.1).\n     - CVE-2026-33006\n   * SECURITY UPDATE: mod_proxy_ajp ajp_msg_check_header bounds-check fix\n     - debian/patches/CVE-2026-28780.patch: tighten the upper-bound check in\n       ajp_msg_check_header() to reserve AJP_HEADER_LEN bytes of headroom in\n       modules/proxy/ajp_msg.c (companion to CVE-2026-33857/34032).\n     - CVE-2026-28780","modified":"2026-06-04T10:03:59.529695216Z","published":"2026-05-18T15:38:03Z","upstream":["CVE-2026-24072","CVE-2026-28780","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu18.04els/CLSA-2026-1779118679.html"}],"affected":[{"package":{"name":"apache2","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-bin","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-bin?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-data","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-data?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-dev","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-dev?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-doc","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-doc?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-ssl-dev","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-ssl-dev?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-suexec-custom","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-suexec-custom?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-suexec-pristine","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-suexec-pristine?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}},{"package":{"name":"apache2-utils","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/apache2-utils?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.29-1ubuntu4.27+tuxcare.els9"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2026-1779118679.json"}}],"schema_version":"1.7.5"}