{"id":"CLSA-2026-1779118869","summary":"Fix of 8 CVEs","details":"   * SECURITY UPDATE: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions\n     - debian/patches/CVE-2026-33857-prereq.patch: prerequisite fix for\n       ajp_msg_check_header bounds check to keep msg-\u003elen within buffer\n     - debian/patches/CVE-2026-33857.patch: fix off-by-one out-of-bounds read in mod_proxy_ajp message getter functions\n     - CVE-2026-33857\n   * SECURITY UPDATE: fix improper null termination and out-of-bounds read in ajp_msg_get_string\n     - debian/patches/CVE-2026-34032.patch: fix improper null termination and out-of-bounds read in ajp_msg_get_string\n     - CVE-2026-34032\n   * SECURITY UPDATE: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data\n     - debian/patches/CVE-2026-34059.patch: fix heap buffer over-read in mod_proxy_ajp ajp_parse_data\n     - CVE-2026-34059\n   * SECURITY UPDATE: use restricted ap_expr parser in htaccess context to prevent local privilege escalation\n     - debian/patches/CVE-2026-24072.patch: use restricted ap_expr parser in htaccess context to prevent local privilege escalation\n     - CVE-2026-24072\n   * SECURITY UPDATE: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks\n     - debian/patches/CVE-2026-29169.patch: fix NULL pointer dereference crash in mod_dav_lock dav_generic_refresh_locks\n     - CVE-2026-29169\n   * SECURITY UPDATE: fix timing attack allowing Digest authentication bypass in mod_auth_digest\n     - debian/patches/CVE-2026-33006.patch: fix timing attack allowing Digest authentication bypass in mod_auth_digest\n     - CVE-2026-33006\n   * SECURITY UPDATE: fix NULL pointer dereference crash in mod_authn_socache\n     - debian/patches/CVE-2026-33007.patch: fix NULL pointer dereference crash in mod_authn_socache\n     - CVE-2026-33007\n   * SECURITY UPDATE: fix HTTP response splitting via newlines/controls in outgoing status line\n     - debian/patches/CVE-2026-33523.patch: fix HTTP response splitting via newlines/controls in outgoing status line\n     - CVE-2026-33523","modified":"2026-06-04T10:04:41.452823753Z","published":"2026-05-19T00:19:25Z","upstream":["CVE-2026-24072","CVE-2026-29169","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/debian10els/CLSA-2026-1779118869.html"}],"affected":[{"package":{"name":"apache2","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-bin","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-bin?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-data","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-data?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-doc","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-doc?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-ssl-dev","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-ssl-dev?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-suexec-custom","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-suexec-custom?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-suexec-pristine","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-suexec-pristine?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"apache2-utils","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/apache2-utils?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"libapache2-mod-md","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libapache2-mod-md?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}},{"package":{"name":"libapache2-mod-proxy-uwsgi","ecosystem":"TuxCare:Debian:10","purl":"pkg:deb/tuxcare/libapache2-mod-proxy-uwsgi?distro=debian-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.59-1~deb10u1+tuxcare.els5"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/debian10els/CLSA-2026-1779118869.json"}}],"schema_version":"1.7.5"}