[El-errata] ELSA-2026-41906 Important: Oracle Linux 9 httpd security, bug fix, and enhancement update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Wed Jul 22 11:24:19 UTC 2026


Oracle Linux Security Advisory ELSA-2026-41906

http://linux.oracle.com/errata/ELSA-2026-41906.html

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

x86_64:
httpd-2.4.62-13.0.1.el9_8.5.x86_64.rpm
httpd-core-2.4.62-13.0.1.el9_8.5.x86_64.rpm
httpd-devel-2.4.62-13.0.1.el9_8.5.x86_64.rpm
httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-tools-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_ldap-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_lua-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_proxy_html-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_session-2.4.62-13.0.1.el9_8.5.x86_64.rpm
mod_ssl-2.4.62-13.0.1.el9_8.5.x86_64.rpm

aarch64:
httpd-2.4.62-13.0.1.el9_8.5.aarch64.rpm
httpd-core-2.4.62-13.0.1.el9_8.5.aarch64.rpm
httpd-devel-2.4.62-13.0.1.el9_8.5.aarch64.rpm
httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm
httpd-tools-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_ldap-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_lua-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_proxy_html-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_session-2.4.62-13.0.1.el9_8.5.aarch64.rpm
mod_ssl-2.4.62-13.0.1.el9_8.5.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol9/SRPMS-updates/httpd-2.4.62-13.0.1.el9_8.5.src.rpm

Related CVEs:

CVE-2024-42516
CVE-2026-24072
CVE-2026-29169
CVE-2026-33006
CVE-2026-34355
CVE-2026-34356
CVE-2026-42535
CVE-2026-42536
CVE-2026-43951
CVE-2026-44119
CVE-2026-44185
CVE-2026-44186
CVE-2026-44631




Description of changes:

[2.4.62-13.0.1.el9_8.5]
- Replace index.html with Oracle's index page oracle_index.html.

[2.4.62-13.5]
- Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix

[2.4.62-13.4]
- Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow
  via malicious backend servers (CVE-2026-34356)
- Resolves: RHEL-182578 - httpd: incomplete fix
  for CVE-2023-38709 (CVE-2024-42516)
- Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951,
  CVE-2026-44119, CVE-2026-44186

[2.4.62-13.3]
- Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling
  vulnerability (CVE-2026-34355)
- Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery
  (CVE-2026-29169)
- Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto
  (CVE-2026-42536)
- Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement
  bug in mod_ssl (CVE-2026-44185)

[2.4.62-13.2]
- Resolves: RHEL-184312 - httpd: ap_regname restrict to reasonable captures
  (CVE-2026-44631)

[2.4.62-13.1]
- Resolves: RHEL-173555 - httpd: Apache HTTP Server mod_proxy_ajp: Arbitrary
  code execution via heap-based buffer overflow (CVE-2026-28780)
- Resolves: RHEL-175080 - httpd: NULL pointer dereference can cause a child
  process crash (CVE-2026-33007)
- Resolves: RHEL-175100 - httpd: off-by-one out-of-bounds reads in AJP getter
  functions (CVE-2026-33857)
- Resolves: RHEL-175028 - httpd: heap-based buffer over-read due to missing
  null-termination check (CVE-2026-34032)
- Resolves: RHEL-175062 - httpd: heap-based buffer over-read and memory
  disclosure in ajp_parse_data() (CVE-2026-34059)




More information about the El-errata mailing list