Alerts This Week
Warning Icon 1 1,308
Alerts This Week
Warning Icon 1 1,308

Ubuntu 22.04 LTS: Apache Critical DoS and Code Exec USN-7968-1

ubuntu
Calendar Grey January 19, 2026
Dist Ubuntu Esm H88
Apache HTTP Server on Ubuntu has critical fixes for denial of service and remote code execution vulnerabilities.
Several security issues were fixed in Apache HTTP Server.

Summary

Several security issues were fixed in Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

Details:

It was discovered that the Apache HTTP Server incorrectly handled failed

ACME certificate renewals. This could result in renewal attempts to be

repeated without delays, possibly leading to a denial of service.

(CVE-2025-55753)

Anthony Parfenov discovered that the Apache HTTP Server would pass the

query string to cmd directives when configured with Server Side Includes

(SSI) enabled and mod_cgid. An attacker could possibly use this issue to

execute arbitrary code. (CVE-2025-58098)

Mattias �sander discovered that the Apache HTTP Server incorrectly

neutralized certain environment variables. This could result in

unexpectedly superseding variables calculated by the server for CGI

programs. (CVE-2025-65082)

Mattias �sander discovered that the Apache HTTP Server incorrectly

handled AllowOverride FileInfo configurations when using mod_userdir with

suexec. An atta...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  apache2                         2.4.64-1ubuntu3.2

Ubuntu 24.04 LTS
  apache2                         2.4.58-1ubuntu8.10

Ubuntu 22.04 LTS
  apache2                         2.4.52-1ubuntu4.18

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7968-1

CVE-2025-55753, CVE-2025-58098, CVE-2025-65082, CVE-2025-66200

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7968-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here