[El-errata] ELSA-2026-21433 Important: Oracle Linux 10 httpd security update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Mon Jul 20 18:57:07 UTC 2026
Oracle Linux Security Advisory ELSA-2026-21433
http://linux.oracle.com/errata/ELSA-2026-21433.html
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:
x86_64:
httpd-2.4.63-13.0.1.el10_2.4.x86_64.rpm
httpd-core-2.4.63-13.0.1.el10_2.4.x86_64.rpm
httpd-devel-2.4.63-13.0.1.el10_2.4.x86_64.rpm
httpd-filesystem-2.4.63-13.0.1.el10_2.4.noarch.rpm
httpd-manual-2.4.63-13.0.1.el10_2.4.noarch.rpm
httpd-tools-2.4.63-13.0.1.el10_2.4.x86_64.rpm
mod_ldap-2.4.63-13.0.1.el10_2.4.x86_64.rpm
mod_lua-2.4.63-13.0.1.el10_2.4.x86_64.rpm
mod_proxy_html-2.4.63-13.0.1.el10_2.4.x86_64.rpm
mod_session-2.4.63-13.0.1.el10_2.4.x86_64.rpm
mod_ssl-2.4.63-13.0.1.el10_2.4.x86_64.rpm
aarch64:
httpd-2.4.63-13.0.1.el10_2.4.aarch64.rpm
httpd-core-2.4.63-13.0.1.el10_2.4.aarch64.rpm
httpd-devel-2.4.63-13.0.1.el10_2.4.aarch64.rpm
httpd-filesystem-2.4.63-13.0.1.el10_2.4.noarch.rpm
httpd-manual-2.4.63-13.0.1.el10_2.4.noarch.rpm
httpd-tools-2.4.63-13.0.1.el10_2.4.aarch64.rpm
mod_ldap-2.4.63-13.0.1.el10_2.4.aarch64.rpm
mod_lua-2.4.63-13.0.1.el10_2.4.aarch64.rpm
mod_proxy_html-2.4.63-13.0.1.el10_2.4.aarch64.rpm
mod_session-2.4.63-13.0.1.el10_2.4.aarch64.rpm
mod_ssl-2.4.63-13.0.1.el10_2.4.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/httpd-2.4.63-13.0.1.el10_2.4.src.rpm
Related CVEs:
CVE-2026-28780
CVE-2026-33007
CVE-2026-33857
CVE-2026-34032
CVE-2026-34059
Description of changes:
[2.4.63-13.0.1.el10_2.4]
- Replace index.html with Oracle's index page oracle_index.html.
[2.4.63-13.4]
- Resolves: RHEL-186221 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-186195 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via untrusted content in mod_xml2enc (CVE-2026-42536)
- Resolves: RHEL-186182 - httpd: Apache HTTP Server: Buffer overflow in
mod_proxy_html allows security bypass (CVE-2026-34355)
- Resolves: RHEL-186158 - httpd: Apache HTTP Server: Buffer Over-read via
outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
- Resolves: RHEL-184305 - httpd: Apache HTTP Server: Denial of Service via
crafted regular expressions (CVE-2026-44631)
- Resolves : RHEL-182581 - httpd: incomplete fix for
CVE-2023-38709 (CVE-2024-42516)
- Resolves: RHEL-175621 - httpd: NULL pointer dereference via specially crafted
request (CVE-2026-29169)
- Also addresses CVE-2026-44119, CVE-2026-44186, CVE-2026-42535,
CVE-2026-24072, CVE-2026-33006, CVE-2026-43951
[2.4.63-13.1]
- Resolves: RHEL-173549 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175065 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175095 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175039 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175050 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)
More information about the El-errata
mailing list