Security update for apache2
| Announcement ID: | SUSE-SU-2026:2104-1 |
|---|---|
| Release Date: | 2026-05-28T14:03:06Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 11 vulnerabilities can now be installed.
Description:
This update for apache2 fixes the following issues
- CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957).
- CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935).
- CVE-2026-28780: heap buffer overflow in
mod_proxy_ajpviaajp_msg_check_header()(bsc#1264163). - CVE-2026-29168: allocation of resources without limits in
mod_mdvia OCSP response (bsc#1264150). - CVE-2026-29169: NULL pointer dereference in
mod_dav_lockallows server crash via malicious requests (bsc#1263956). - CVE-2026-33006:
mod_auth_digesttiming attack allows bypass of Digest authentication (bsc#1263955). - CVE-2026-33007: NULL pointer dereference in
mod_authn_socacheallows unauthenticated remote user to crash a child processes (bsc#1263954). - CVE-2026-33523: HTTP response splitting forwarding malicious status line (bsc#1263953).
- CVE-2026-33857: off-by-one OOB reads in AJP getter functions (bsc#1263952).
- CVE-2026-34032: heap buffer overread in
mod_proxy_ajpdue to missing null-termination check (bsc#1263951). - CVE-2026-34059: heap buffer overread and memory disclosure via
ajp_parse_data()(bsc#1263950).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Package Hub 15 15-SP7
zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2104=1 -
Server Applications Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2104=1 -
Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2104=1
Package List:
-
SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64)
- apache2-event-2.4.66-150700.4.20.1
- apache2-event-debugsource-2.4.66-150700.4.20.1
- apache2-event-debuginfo-2.4.66-150700.4.20.1
-
Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64)
- apache2-utils-debugsource-2.4.66-150700.4.20.1
- apache2-utils-debuginfo-2.4.66-150700.4.20.1
- apache2-devel-2.4.66-150700.4.20.1
- apache2-worker-2.4.66-150700.4.20.1
- apache2-worker-debugsource-2.4.66-150700.4.20.1
- apache2-utils-2.4.66-150700.4.20.1
- apache2-worker-debuginfo-2.4.66-150700.4.20.1
-
Server Applications Module 15-SP7 (noarch)
- apache2-manual-2.4.66-150700.4.20.1
-
Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
- apache2-2.4.66-150700.4.20.1
- apache2-debuginfo-2.4.66-150700.4.20.1
- apache2-prefork-debugsource-2.4.66-150700.4.20.1
- apache2-debugsource-2.4.66-150700.4.20.1
- apache2-prefork-debuginfo-2.4.66-150700.4.20.1
- apache2-prefork-2.4.66-150700.4.20.1
References:
- https://www.suse.com/security/cve/CVE-2026-23918.html
- https://www.suse.com/security/cve/CVE-2026-24072.html
- https://www.suse.com/security/cve/CVE-2026-28780.html
- https://www.suse.com/security/cve/CVE-2026-29168.html
- https://www.suse.com/security/cve/CVE-2026-29169.html
- https://www.suse.com/security/cve/CVE-2026-33006.html
- https://www.suse.com/security/cve/CVE-2026-33007.html
- https://www.suse.com/security/cve/CVE-2026-33523.html
- https://www.suse.com/security/cve/CVE-2026-33857.html
- https://www.suse.com/security/cve/CVE-2026-34032.html
- https://www.suse.com/security/cve/CVE-2026-34059.html
- https://bugzilla.suse.com/show_bug.cgi?id=1263935
- https://bugzilla.suse.com/show_bug.cgi?id=1263950
- https://bugzilla.suse.com/show_bug.cgi?id=1263951
- https://bugzilla.suse.com/show_bug.cgi?id=1263952
- https://bugzilla.suse.com/show_bug.cgi?id=1263953
- https://bugzilla.suse.com/show_bug.cgi?id=1263954
- https://bugzilla.suse.com/show_bug.cgi?id=1263955
- https://bugzilla.suse.com/show_bug.cgi?id=1263956
- https://bugzilla.suse.com/show_bug.cgi?id=1263957
- https://bugzilla.suse.com/show_bug.cgi?id=1264150
- https://bugzilla.suse.com/show_bug.cgi?id=1264163