Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Ubuntu 22.04 LTS: Apache Critical DoS and Code Exec USN-7968-1

Ubuntu Large Esm H500
Several security issues were fixed in Apache HTTP Server.
==========================================================================
Ubuntu Security Notice USN-7968-1
January 19, 2026

apache2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in Apache HTTP Server.

Software Description:
- apache2: Apache HTTP server

Details:

It was discovered that the Apache HTTP Server incorrectly handled failed
ACME certificate renewals. This could result in renewal attempts to be
repeated without delays, possibly leading to a denial of service.
(CVE-2025-55753)

Anthony Parfenov discovered that the Apache HTTP Server would pass the
query string to cmd directives when configured with Server Side Includes
(SSI) enabled and mod_cgid. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2025-58098)

Mattias �sander discovered that the Apache HTTP Server incorrectly
neutralized certain environment variables. This could result in
unexpectedly superseding variables calculated by the server for CGI
programs. (CVE-2025-65082)

Mattias �sander discovered that the Apache HTTP Server incorrectly
handled AllowOverride FileInfo configurations when using mod_userdir with
suexec. An attacker with access to use the RequestHeader directive in
htaccess can cause some CGI scripts to run under an unexpected userid.
(CVE-2025-66200)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  apache2                         2.4.64-1ubuntu3.2

Ubuntu 24.04 LTS
  apache2                         2.4.58-1ubuntu8.10

Ubuntu 22.04 LTS
  apache2                         2.4.52-1ubuntu4.18

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-7968-1
  CVE-2025-55753, CVE-2025-58098, CVE-2025-65082, CVE-2025-66200

Package Information:
  https://launchpad.net/ubuntu/+source/apache2/2.4.64-1ubuntu3.2
  https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.10
  https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.18

Ubuntu 22.04 LTS: Apache Critical DoS and Code Exec USN-7968-1

ubuntu
Calendar Grey January 19, 2026
Dist Ubuntu Esm H88
Apache HTTP Server on Ubuntu has critical fixes for denial of service and remote code execution vulnerabilities.
Several security issues were fixed in Apache HTTP Server.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: It was discovered that the Apache HTTP Server incorrectly handled failed ACME certificate renewals. This could result in renewal attempts to be repeated without delays, possibly leading to a denial of service. (CVE-2025-55753) Anthony Parfenov discovered that the Apache HTTP Server would pass the query string to cmd directives when configured with Server Side Includes (SSI) enabled and mod_cgid. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-58098) Mattias �sander discovered that the Apache HTTP Server incorrectly neutralized certain environment variables. This could result in unexpectedly superseding variables calculated by the server for CGI programs. (CVE-2025-65082) Mattias �sander disc...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 apache2 2.4.64-1ubuntu3.2 Ubuntu 24.04 LTS apache2 2.4.58-1ubuntu8.10 Ubuntu 22.04 LTS apache2 2.4.52-1ubuntu4.18 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7968-1

CVE-2025-55753, CVE-2025-58098, CVE-2025-65082, CVE-2025-66200

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7968-1

Package Information

https://launchpad.net/ubuntu/+source/apache2/2.4.64-1ubuntu3.2 https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.10 https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.18

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here