Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 479
Alerts This Week
Warning Icon 1 479

Mageia Apache Critical Security Issues Advisory 2026-0289 CVE-2026-29167

mageia
Calendar Grey July 23, 2026
Scroller Mageia
Multiple security issues in Apache HTTP Server addressed with Mageia updates. Important for system integrity and service continuity.
Mageia released updates for security vulnerabilities in Apache HTTP Server affecting versions 10 and 9, addressing multiple issues including buffer overflows and denial of service ...

Summary

Description: The updated packages fix security vulnerabilities: Apache HTTP Server: mod_ldap per-dir use-after-free. (CVE-2026-29167) Apache HTTP Server: mod_proxy_ftp XSS. (CVE-2026-29170) Apache HTTP Server: mod_proxy_html buffer overflow. (CVE-2026-34355) Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow. (CVE-2026-34356) Apache HTTP Server: mod_dav_fs protected directory access. (CVE-2026-42535) Apache HTTP Server: mod_xml2enc heap overflow. (CVE-2026-42536) Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash. (CVE-2026-43951) Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules. (CVE-2026-44119) Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`. (CVE-2026-44185) Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp. (CVE-2026-44186) Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow. (CVE-2026-44631) Apache HTTP Server: mod_http2 memory corrup...

References

- https://bugs.mageia.org/show_bug.cgi?id=35625

- https://www.openwall.com/lists/oss-security/2026/06/03/3

- https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb

- https://lists.debian.org/debian-security-announce/2026/msg00234.html

- https://www.openwall.com/lists/oss-security/2026/06/08/4

- https://www.openwall.com/lists/oss-security/2026/06/08/5

- https://www.openwall.com/lists/oss-security/2026/06/08/6

- https://www.openwall.com/lists/oss-security/2026/06/08/7

- https://www.openwall.com/lists/oss-security/2026/06/08/8

- https://www.openwall.com/lists/oss-security/2026/06/08/9

- https://www.openwall.com/lists/oss-security/2026/06/08/10

- https://www.openwall.com/lists/oss-security/2026/06/08/11

- https://www.openwall.com/lists/oss-security/2026/06/08/12

- https://www.openwall.com/lists/oss-security/2026/06/08/13

- https://www.openwall.com/lists/oss-security/2026/06/08/14

- https://www.openwall.com/lists/oss-security/2026/06/08/15

- https://www.openwall.com/lists/oss-security/2026/06/08/16

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7R2KWQ6IEDZQHPWK66QN6DG4LW6X3OUM/

- https://www.cve.org/CVERecord?id=CVE-2026-29167

- https://www.cve.org/CVERecord?id=CVE-2026-29170

- https://www.cve.org/CVERecord?id=CVE-2026-34355

- https://www.cve.org/CVERecord?id=CVE-2026-34356

- https://www.cve.org/CVERecord?id=CVE-2026-42535

- https://www.cve.org/CVERecord?id=CVE-2026-42536

- https://www.cve.org/CVERecord?id=CVE-2026-43951

- https://www.cve.org/CVERecord?id=CVE-2026-44119

- https://www.cve.org/CVERecord?id=CVE-2026-44185

- https://www.cve.org/CVERecord?id=CVE-2026-44186

- https://www.cve.org/CVERecord?id=CVE-2026-44631

- https://www.cve.org/CVERecord?id=CVE-2026-48913

- https://www.cve.org/CVERecord?id=CVE-2026-49975

Resolution

SRPMS

- 10/core/apache-2.4.68-1.mga10

- 9/core/apache-2.4.68-1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 23 Jul 2026 
URL: https://advisories.mageia.org/MGASA-2026-0289.html
Type: security
CVE: CVE-2026-29167, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356, CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119, CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913, CVE-2026-49975

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.