[El-errata] ELSA-2026-41906 Important: Oracle Linux 9 httpd security, bug fix, and enhancement update
Errata Announcements for Oracle Linux
el-errata at oss.oracle.com
Wed Jul 22 11:24:19 UTC 2026
Oracle Linux Security Advisory ELSA-2026-41906
http://linux.oracle.com/errata/ELSA-2026-41906.html
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
x86_64:
httpd-2.4.62-13.0.1.el9_8.5.x86_64.rpm
httpd-core-2.4.62-13.0.1.el9_8.5.x86_64.rpm
httpd-devel-2.4.62-13.0.1.el9_8.5.x86_64.rpm
httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-tools-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_ldap-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_lua-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_proxy_html-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_session-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_ssl-2.4.62-13.0.1.el9_8.5.x86_64.rpm
aarch64:
httpd-2.4.62-13.0.1.el9_8.5.aarch64.rpm
httpd-core-2.4.62-13.0.1.el9_8.5.aarch64.rpm
httpd-devel-2.4.62-13.0.1.el9_8.5.aarch64.rpm
httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-tools-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_ldap-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_lua-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_proxy_html-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_session-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_ssl-2.4.62-13.0.1.el9_8.5.aarch64.rpm
SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/httpd-2.4.62-13.0.1.el9_8.5.src.rpm
Related CVEs:
CVE-2024-42516
CVE-2026-24072
CVE-2026-29169
CVE-2026-33006
CVE-2026-34355
CVE-2026-34356
CVE-2026-42535
CVE-2026-42536
CVE-2026-43951
CVE-2026-44119
CVE-2026-44185
CVE-2026-44186
CVE-2026-44631
Description of changes:
[2.4.62-13.0.1.el9_8.5]
- Replace index.html with Oracle's index page oracle_index.html.
[2.4.62-13.5]
- Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix
[2.4.62-13.4]
- Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-182578 - httpd: incomplete fix
for CVE-2023-38709 (CVE-2024-42516)
- Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951,
CVE-2026-44119, CVE-2026-44186
[2.4.62-13.3]
- Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling
vulnerability (CVE-2026-34355)
- Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery
(CVE-2026-29169)
- Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto
(CVE-2026-42536)
- Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement
bug in mod_ssl (CVE-2026-44185)
[2.4.62-13.2]
- Resolves: RHEL-184312 - httpd: ap_regname restrict to reasonable captures
(CVE-2026-44631)
[2.4.62-13.1]
- Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child
process crash (CVE-2026-33007)
- Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter
functions (CVE-2026-33857)
- Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing
null-termination check (CVE-2026-34032)
- Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory
disclosure in ajp_parse_data() (CVE-2026-34059)
More information about the El-errata
mailing list