Alerts This Week
Warning Icon 1 938
Alerts This Week
Warning Icon 1 938

Ubuntu 25.10 Apache2 Regression Patch USN-7968-2 CVE-2025-55753

ubuntu
Calendar Grey March 9, 2026
Dist Ubuntu Esm H88
A regression in Apache HTTP Server on Ubuntu caused issues; patch recommended for security updates and fixes.
USN-7968-1 introduced a regression in Apache HTTP Server

Summary

USN-7968-1 introduced a regression in Apache HTTP Server

Software Description:

- apache2: Apache HTTP server

Details:

USN-7968-1 fixed vulnerabilities in Apache HTTP Server. The update

introduced a regression in mod_md where the MDStapleOthers setting was

ignored which resulted in OCSP being broken for some domains. This update

fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that the Apache HTTP Server incorrectly handled failed

ACME certificate renewals. This could result in renewal attempts to be

repeated without delays, possibly leading to a denial of service.

(CVE-2025-55753)

Anthony Parfenov discovered that the Apache HTTP Server would pass the

query string to cmd directives when configured with Server Side Includes

(SSI) enabled and mod_cgid. An attacker could possibly use this issue to

execute arbitrary code. (CVE-2025-58098)

Mattias �sander discovered that the Apache HTTP Server incorrectly

neutralized ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  apache2                         2.4.64-1ubuntu3.3

Ubuntu 24.04 LTS
  apache2                         2.4.58-1ubuntu8.11

Ubuntu 22.04 LTS
  apache2                         2.4.52-1ubuntu4.19

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7968-2

https://ubuntu.com/security/notices/USN-7968-1

https://bugs.launchpad.net/bugs/2142766

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7968-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here