This update for apache2 fixes the following issues:
- CVE-2025-55753: Fixed mod_md (ACME), unintended retry intervals (bsc#1254511)
- CVE-2025-58098: Fixed Server Side Includes adds query string to #exec cmd (bsc#1254512)
- CVE-2025-65082: Fixed CGI environment variable override (bsc#1254514)
- CVE-2025-66200: Fixed mod_userdir+suexec bypass via AllowOverride FileInfo (bsc#1254515)
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-139=1
- openSUSE Leap 16.0:
apache2-2.4.63-160000.3.1
apache2-devel-2.4.63-160000.3.1
apache2-event-2.4.63-160000.3.1
apache2-manual-2.4.63-160000.3.1
apache2-prefork-2.4.63-160000.3.1
apache2-utils-2.4.63-160000.3.1
apache2-worker-2.4.63-160000.3.1
* bsc#1254511
* bsc#1254512
* bsc#1254514
* bsc#1254515
References:
* https://www.suse.com/security/cve/CVE-2025-55753.html
* https://www.suse.com/security/cve/CVE-2025-58098.html
* https://www.suse.com/security/cve/CVE-2025-65082.html
* https://www.suse.com/security/cve/CVE-2025-66200.html
Get the latest Linux and open source security news straight to your inbox.