Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Oracle Linux 9 HTTPD Important Buffer Overflow Fix ELSA-2026-41906

oracle
Calendar Grey July 22, 2026
Scroller Oracle
Updated Oracle Linux 9 packages released addressing key security issues including buffer overflow and code execution threats.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[2.4.62-13.0.1.el9_8.5] - Replace index.html with Oracle's index page oracle_index.html. [2.4.62-13.5] - Resolves: RHEL-192752 - mod_proxy_html regression in CVE-2026-34355 fix [2.4.62-13.4] - Resolves: RHEL-186217 - httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356) - Resolves: RHEL-182578 - httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) - Also addresses CVE-2026-24072, CVE-2026-33006, CVE-2026-42535, CVE-2026-43951, CVE-2026-44119, CVE-2026-44186 [2.4.62-13.3] - Resolves: RHEL-186186 - httpd: mod_proxy_html buffer handling vulnerability (CVE-2026-34355) - Resolves: RHEL-175636 - httpd: mod_dav_lock uses wrong lock discovery (CVE-2026-29169) - Resolves: RHEL-186196 - mod_xml2enc: fix bblen accounting in fix_skipto (CVE-2026-42536) - Resolves: RHEL-186164 - httpd: fix OCSP write buffer advancement bug in mod_ssl (CVE-2026-44185) [2.4.62-13.2] - Resolves: RHEL-184312 - httpd: ap_regname restrict to reason...

Read the Full Advisory

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates/httpd-2.4.62-13.0.1.el9_8.5.src.rpm

x86_64

httpd-2.4.62-13.0.1.el9_8.5.x86_64.rpm httpd-core-2.4.62-13.0.1.el9_8.5.x86_64.rpm httpd-devel-2.4.62-13.0.1.el9_8.5.x86_64.rpm httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpm httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm httpd-tools-2.4.62-13.0.1.el9_8.5.x86_64.rpm mod_ldap-2.4.62-13.0.1.el9_8.5.x86_64.rpm mod_lua-2.4.62-13.0.1.el9_8.5.x86_64.rpm mod_proxy_html-2.4.62-13.0.1.el9_8.5.x86_64.rpm mod_session-2.4.62-13.0.1.el9_8.5.x86_64.rpm mod_ssl-2.4.62-13.0.1.el9_8.5.x86_64.rpm

aarch64

httpd-2.4.62-13.0.1.el9_8.5.aarch64.rpm httpd-core-2.4.62-13.0.1.el9_8.5.aarch64.rpm httpd-devel-2.4.62-13.0.1.el9_8.5.aarch64.rpm httpd-filesystem-2.4.62-13.0.1.el9_8.5.noarch.rpm httpd-manual-2.4.62-13.0.1.el9_8.5.noarch.rpm httpd-tools-2.4.62-13.0.1.el9_8.5.aarch64.rpm mod_ldap-2.4.62-13.0.1.el9_8.5.aarch64.rpm mod_lua-2.4.62-13.0.1.el9_8.5.aarch64.rpm mod_proxy_html-2.4.62-13.0.1.el9_8.5.aarch64.rpm mod_session-2.4.62-13.0.1.el9_8.5.aarch64.rpm mod_ssl-2.4.62-13.0.1.el9_8.5.aarch64.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2024-42516 CVE-2026-24072 CVE-2026-29169 CVE-2026-33006 CVE-2026-34355 CVE-2026-34356 CVE-2026-42535 CVE-2026-42536 CVE-2026-43951 CVE-2026-44119 CVE-2026-44185 CVE-2026-44186 CVE-2026-44631

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.