Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 66 vulnerabilities and contains one feature can now be installed.. # Security update for apache2 Announcement ID: SUSE-SU-2026:2686-1 Release Date: 2026-06-29T22:36:09Z Rating: important References: * bsc#1207327 * bsc#1208708 * bsc#1214357 * bsc#1263935 * bsc#1263950 * bsc#1263951 * bsc#1263952 * bsc#1263953 * bsc#1263954 * bsc#1263955 * bsc#1263956 * bsc#1263957 * bsc#1264150 * bsc#1264163 * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 * bsc#690734 * jsc#PED-16334 Cross-References: * CVE-2006-20001 * CVE-2021-44224 * CVE-2021-44790 * CVE-2022-22719 * CVE-2022-22720 * CVE-2022-22721 * CVE-2022-23943 * CVE-2022-26377 * CVE-2022-28614 * CVE-2022-28615 * CVE-2022-29404 * CVE-2022-30522 * CVE-2022-30556 * CVE-2022-31813 * CVE-2022-36760 * CVE-2022-37436 * CVE-2023-25690 * CVE-2023-27522 * CVE-2023-31122 * CVE-2023-38709 * CVE-2023-45802 * CVE-2024-24795 * CVE-2024-27316 * CVE-2024-38473 * CVE-2024-38474 * CVE-2024-38475 * CVE-2024-38476 * CVE-2024-38477 * CVE-2024-39573 * CVE-2024-39884 * CVE-2024-40725 * CVE-2024-42516 * CVE-2024-43204 * CVE-2024-47252 * CVE-2025-23048 * CVE-2025-49630 * CVE-2025-49812 * CVE-2025-53020 * CVE-2025-55753 * CVE-2025-58098 * CVE-2025-65082 * CVE-2025-66200 * CVE-2026-23918 * CVE-2026-24072 * CVE-2026-28780 * CVE-2026-29167 * CVE-2026-29168 * CVE-2026-29169 * CVE-2026-29170 * CVE-2026-33006 * CVE-2026-33007 * CVE-2026-33523 * CVE-2026-33857 * CVE-2026-34032 * CVE-2026-34059 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2006-20001 ( SUSE ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2006-20001 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2021-44224 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2021-44224 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2021-44790 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2021-44790 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-22719 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-22719 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-22720 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2022-22720 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-22721 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2022-22721 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2022-23943 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2022-23943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-26377 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2022-26377 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2022-28614 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-28614 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2022-28615 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2022-28615 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2022-28615 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2022-29404 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-29404 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-30522 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-30522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-30556 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-30556 ( NVD ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-31813 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2022-31813 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-36760 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2022-36760 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2022-36760 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2022-37436 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2022-37436 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2022-37436 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2023-25690 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-25690 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-25690 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-27522 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-27522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-27522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-31122 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-31122 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-38709 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2023-38709 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2023-45802 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45802 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-24795 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2024-24795 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2024-27316 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-27316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-27316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-38473 ( SUSE ): 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-38473 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-38474 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2024-38474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-38474 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2024-38475 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2024-38475 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-38475 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-38476 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2024-38476 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-38476 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2024-38477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-38477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-38477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-39573 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2024-39573 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-39884 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-39884 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-40725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-40725 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-40725 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-42516 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-42516 ( SUSE ): 4.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N * CVE-2024-42516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-43204 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-43204 ( SUSE ): 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2024-43204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-47252 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-47252 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-47252 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-23048 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-23048 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-23048 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-49630 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-49630 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49630 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-49812 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-49812 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2025-49812 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-53020 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-53020 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-53020 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-55753 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-55753 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-55753 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-58098 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-58098 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-58098 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-65082 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N *CVE-2025-65082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2025-65082 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-66200 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-66200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-66200 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-23918 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23918 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23918 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23918 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-24072 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-24072 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-28780 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-28780 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-28780 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-28780 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29168 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29168 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29168 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29169 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29169 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29169 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33006 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33006 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33006 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-33007 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33007 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33007 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33523 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-33523 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-33523 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-33857 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-33857 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-33857 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34032 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34032 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-34032 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34059 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34059 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-34059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 66 vulnerabilities and contains one feature can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957). * CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935). * CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163). * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150). * CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956). *CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955). * CVE-2026-33007: NULL pointer dereference in `mod_authn_socache` allows unauthenticated remote user to crash a child processes (bsc#1263954). * CVE-2026-33523: HTTP response splitting forwarding malicious status line (bsc#1263953). * CVE-2026-33857: off-by-one OOB reads in AJP getter functions (bsc#1263952). * CVE-2026-34032: heap buffer overread in `mod_proxy_ajp` due to missing null- termination check (bsc#1263951). * CVE-2026-34059: heap buffer overread and memory disclosure via `ajp_parse_data()` (bsc#1263950). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). Non security issue: * Update to 2.4.66 (jsc#PED-16334). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypperpatch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2686=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2686=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2686=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2686=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2686=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2686=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2686=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2686=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2686=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 *apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-event-debuginfo-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-event-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * apache2-example-pages-2.4.66-150400.6.57.1 * openSUSE Leap 15.4 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 *apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 *apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * apache2-doc-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-debugsource-2.4.66-150400.6.57.1 * apache2-worker-debuginfo-2.4.66-150400.6.57.1 * apache2-2.4.66-150400.6.57.1 * apache2-prefork-2.4.66-150400.6.57.1 * apache2-prefork-debuginfo-2.4.66-150400.6.57.1 * apache2-devel-2.4.66-150400.6.57.1 * apache2-utils-2.4.66-150400.6.57.1 * apache2-utils-debuginfo-2.4.66-150400.6.57.1 * apache2-worker-2.4.66-150400.6.57.1 * apache2-debuginfo-2.4.66-150400.6.57.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * apache2-doc-2.4.66-150400.6.57.1 ## References: * https://www.suse.com/security/cve/CVE-2006-20001.html * https://www.suse.com/security/cve/CVE-2021-44224.html * https://www.suse.com/security/cve/CVE-2021-44790.html * https://www.suse.com/security/cve/CVE-2022-22719.html * https://www.suse.com/security/cve/CVE-2022-22720.html * https://www.suse.com/security/cve/CVE-2022-22721.html * https://www.suse.com/security/cve/CVE-2022-23943.html * https://www.suse.com/security/cve/CVE-2022-26377.html * https://www.suse.com/security/cve/CVE-2022-28614.html * https://www.suse.com/security/cve/CVE-2022-28615.html * https://www.suse.com/security/cve/CVE-2022-29404.html * https://www.suse.com/security/cve/CVE-2022-30522.html * https://www.suse.com/security/cve/CVE-2022-30556.html * https://www.suse.com/security/cve/CVE-2022-31813.html * https://www.suse.com/security/cve/CVE-2022-36760.html * https://www.suse.com/security/cve/CVE-2022-37436.html * https://www.suse.com/security/cve/CVE-2023-25690.html * https://www.suse.com/security/cve/CVE-2023-27522.html * https://www.suse.com/security/cve/CVE-2023-31122.html * https://www.suse.com/security/cve/CVE-2023-38709.html * https://www.suse.com/security/cve/CVE-2023-45802.html * https://www.suse.com/security/cve/CVE-2024-24795.html * https://www.suse.com/security/cve/CVE-2024-27316.html * https://www.suse.com/security/cve/CVE-2024-38473.html * https://www.suse.com/security/cve/CVE-2024-38474.html * https://www.suse.com/security/cve/CVE-2024-38475.html * https://www.suse.com/security/cve/CVE-2024-38476.html * https://www.suse.com/security/cve/CVE-2024-38477.html * https://www.suse.com/security/cve/CVE-2024-39573.html * https://www.suse.com/security/cve/CVE-2024-39884.html * https://www.suse.com/security/cve/CVE-2024-40725.html * https://www.suse.com/security/cve/CVE-2024-42516.html * https://www.suse.com/security/cve/CVE-2024-43204.html * https://www.suse.com/security/cve/CVE-2024-47252.html * https://www.suse.com/security/cve/CVE-2025-23048.html * https://www.suse.com/security/cve/CVE-2025-49630.html * https://www.suse.com/security/cve/CVE-2025-49812.html * https://www.suse.com/security/cve/CVE-2025-53020.html * https://www.suse.com/security/cve/CVE-2025-55753.html * https://www.suse.com/security/cve/CVE-2025-58098.html * https://www.suse.com/security/cve/CVE-2025-65082.html * https://www.suse.com/security/cve/CVE-2025-66200.html * https://www.suse.com/security/cve/CVE-2026-23918.html * https://www.suse.com/security/cve/CVE-2026-24072.html * https://www.suse.com/security/cve/CVE-2026-28780.html * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29168.html * https://www.suse.com/security/cve/CVE-2026-29169.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-33006.html * https://www.suse.com/security/cve/CVE-2026-33007.html * https://www.suse.com/security/cve/CVE-2026-33523.html * https://www.suse.com/security/cve/CVE-2026-33857.html * https://www.suse.com/security/cve/CVE-2026-34032.html *https://www.suse.com/security/cve/CVE-2026-34059.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1207327 * https://bugzilla.suse.com/show_bug.cgi?id=1208708 * https://bugzilla.suse.com/show_bug.cgi?id=1214357 * https://bugzilla.suse.com/show_bug.cgi?id=1263935 * https://bugzilla.suse.com/show_bug.cgi?id=1263950 * https://bugzilla.suse.com/show_bug.cgi?id=1263951 * https://bugzilla.suse.com/show_bug.cgi?id=1263952 * https://bugzilla.suse.com/show_bug.cgi?id=1263953 * https://bugzilla.suse.com/show_bug.cgi?id=1263954 * https://bugzilla.suse.com/show_bug.cgi?id=1263955 * https://bugzilla.suse.com/show_bug.cgi?id=1263956 * https://bugzilla.suse.com/show_bug.cgi?id=1263957 * https://bugzilla.suse.com/show_bug.cgi?id=1264150 * https://bugzilla.suse.com/show_bug.cgi?id=1264163 * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 *https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 * https://bugzilla.suse.com/show_bug.cgi?id=690734 * https://jira.suse.com/browse/PED-16334 . Security update for apache2 addresses 66 vulnerabilities. Prompt installation is recommended to enhance system security.. SUSE Apache Security Update Important Vulnerability Fix. . Severity: Important. LinuxSecurity.com Team
Apport could be tricked into running programs as an administrator.. =========================================================================Ubuntu Security Notice USN-2569-1 April 14, 2015 apport vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS Summary: Apport could be tricked into running programs as an administrator. Software Description: - apport: automatically generate crash reports for debugging Details: Stéphane Graber and Tavis Ormandy independently discovered that Apport incorrectly handled the crash reporting feature. A local attacker could use this issue to gain elevated privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: apport 2.14.7-0ubuntu8.3 Ubuntu 14.04 LTS: apport 2.14.1-0ubuntu3.9 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2569-1 CVE-2015-1318 Package Information: https://launchpad.net/ubuntu/+source/apport/2.14.7-0ubuntu8.3 https://launchpad.net/ubuntu/+source/apport/2.14.1-0ubuntu3.9 . A security flaw within the Apport tool in Ubuntu may enable local users to execute applications with elevated privileges. It's advisable to apply updates promptly.. Ubuntu Apport Security, Privilege Escalation Fix, Ubuntu Security Notice. . Severity: Important. LinuxSecurity.com Team
A ptrace-related vulnerability has been discovered that could allow a local user to gain elevated (root) privileges without authorization.. ` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated kernel fixes security vulnerabilities and updates driversAdvisory ID: RHSA-2003:145-01 Issue date: 2003-05-27 Updated on: 2003-05-27 Product: Red Hat Enterprise Linux Keywords: ptrace x450 Cross references: Obsoletes: CVE Names: CAN-2003-0127 CAN-2003-0244 --------------------------------------------------------------------- 1. Topic: These updated kernel packages address security vulnerabilites, including a potential data corruption scenario. In addition, a number of drivers have been updated, bugs have been resolved, and support for the IBM x450 platform and the Madison processor have been added. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 3. Problem description: The Linux kernel handles the basic functions of the operating system. A ptrace-related vulnerability has been discovered that could allow a local user to gain elevated (root) privileges without authorization. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0127 to this issue. A flaw has been discovered that could potentially lead to data corruption. The scenario only occurs while performing memory mapped file I/O, where the file is simultaneously unlinked and the corresponding file blocks reallocated. Furthermore, the memory mapped must be to a partial page at the end of a file on an ext3 file system. As such, Red Hat considers this scenario unlikely. A flaw has been found in several hash table implementations in the kernel networking code. A remote attacker could send packets with carefully chosen, forged source addresses in such a way as to makeevery routing cache entry get hashed into the same hash chain. The result would be that the kernel would use a disproportionate amount of processor time to deal with new packets, resulting in a remote denial of service attack. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2003-0244 to this issue. In addition, the following drivers have been updated to the version indicated: - e1000: 4.4.19-k1 - e100: 2.1.29-k2 - ips: 6.00.26 - qla2100, qla2200, qla2300: v6.04.01 - tg3 driver to 1.4c - cciss driver to 2.4.44 - mpt fusion: 2.05.00 - aic7xxx to 6.2.32 - aic79xx to 1.3.6 If the system is configured to use alternate drivers, we recommend applying the kudzu errata RHEA-2003:132 prior to updating the kernel. The updated kernel also adds support for the IBM x450 platform and the Madison processor, and incorporates improved support for the hugetlb file system. This file system makes efficient use of the large page size support that the Itanium architecture provides. All users should upgrade to these errata packages, which address these issues. 4. Solution: Release notes, driver notes, and driver disks for this update are available at the following URL: Support Before applying this update, make sure all previously released errata relevant to your system have been applied, especially the additional packages from RHSA-2002:205 and RHSA-2002:206 respectively. The procedure for upgrading the kernel manually is documented at: Support Please read the directions for your architecture carefully before proceeding with the kernel upgrade. Please note that this update is also available via Red Hat Network. Many people find this to be an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Note that you need to select the kernel explicitly on default configurations of up2date. 5. Bug IDsfixed ( for more info): 81349 - Machine with QLogic card hung during RAC QA 81794 - IPF: AS2.1 Errata 2: spare lun patch for VA and XP storage arrays 88301 - RHEL AS2.1 IPF: Seeing MCAs on system while testing Tulip driver 81803 - AS2.1 Errata 2: Fix to serial driver 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: ia64: Available from Red Hat Network: kernel-source-2.4.18-e.31.ia64.rpm Available from Red Hat Network: kernel-smp-2.4.18-e.31.ia64.rpm Available from Red Hat Network: kernel-doc-2.4.18-e.31.ia64.rpm Available from Red Hat Network: kernel-2.4.18-e.31.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: ia64: Available from Red Hat Network: kernel-source-2.4.18-e.31.ia64.rpm Available from Red Hat Network: kernel-smp-2.4.18-e.31.ia64.rpm Available from Red Hat Network: kernel-doc-2.4.18-e.31.ia64.rpm Available from Red Hat Network: kernel-2.4.18-e.31.ia64.rpm 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- ba07dc3a6150a7512fc11f177b909526 2.1AS/en/os/SRPMS/kernel-2.4.18-e.31.src.rpm e0ff58250b006c516f799866f0066e5c 2.1AS/en/os/ia64/kernel-2.4.18-e.31.ia64.rpm 4e578976d53cfd049cf72b3c5e072ae7 2.1AS/en/os/ia64/kernel-doc-2.4.18-e.31.ia64.rpm d83d298a453b3d5c132c24a290b4ea7a 2.1AS/en/os/ia64/kernel-smp-2.4.18-e.31.ia64.rpm 8abaf7731b2447b3232bda41123a4638 2.1AS/en/os/ia64/kernel-source-2.4.18-e.31.ia64.rpm ba07dc3a6150a7512fc11f177b909526 2.1AW/en/os/SRPMS/kernel-2.4.18-e.31.src.rpm e0ff58250b006c516f799866f0066e5c 2.1AW/en/os/ia64/kernel-2.4.18-e.31.ia64.rpm 4e578976d53cfd049cf72b3c5e072ae7 2.1AW/en/os/ia64/kernel-doc-2.4.18-e.31.ia64.rpm d83d298a453b3d5c132c24a290b4ea7a 2.1AW/en/os/ia64/kernel-smp-2.4.18-e.31.ia64.rpm 8abaf7731b2447b3232bda41123a4638 2.1AW/en/os/ia64/kernel-source-2.4.18-e.31.ia64.rpm These packages are GPG signed by Red Hat for security. Our key is available at All Red Hat products You can verify each package with the followingcommand: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 8. References: CVE -CVE-2003-0127 CVE -CVE-2003-0244 9. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. `. A ptrace vulnerability allows local users to gain unauthorized root privileges, posing risks of data corruption and system reliability.. Kernel Update Advisory, Red Hat Security, Ptrace Issue, Elevated Privilege Flaw. . Severity: Critical. LinuxSecurity.com Team
Updated kernel packages for Red Hat Linux 7.1, 7.2, 7.3, and 8.0 are now available. These packages fix a ptrace-related vulnerability that can lead to elevated privileges.. ` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated 2.4 kernel fixes vulnerability Advisory ID: RHSA-2003:098-00 Issue date: 2003-03-17 Updated on: 2003-03-17 Product: Red Hat Linux Keywords: ptrace Cross references: Obsoletes: RHSA-2003:025-20 RHBA-2003:069-12 CVE Names: CAN-2003-0127 --------------------------------------------------------------------- 1. Topic: Updated kernel packages for Red Hat Linux 7.1, 7.2, 7.3, and 8.0 are now available. These packages fix a ptrace-related vulnerability that can lead to elevated (root) privileges. 2. Relevant releases/architectures: Red Hat Linux 7.1 - athlon, i386, i586, i686 Red Hat Linux 7.2 - athlon, i386, i586, i686 Red Hat Linux 7.3 - athlon, i386, i586, i686 Red Hat Linux 8.0 - athlon, i386, i586, i686 3. Problem description: The Linux kernel handles the basic functions of the operating system. A vulnerability has been found in version 2.4.18 of the kernel. This vulnerability makes it possible for local users to gain elevated (root) privileges without authorization. This advisory deals with updates to Red Hat Linux 7.1, 7.2, 7.3, and 8.0. All users of Red Hat Linux 7.1, 7.2, 7.3, and 8.0 should upgrade to these errata packages, which contain patches to fix the vulnerability. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied, especially the additional packages from RHSA-2002:205 and RHSA-2002:206. The procedure for upgrading the kernel manually is documented at: Support Please read the directions for your architecture carefully before proceeding with the kernel upgrade. Please note that this update is also available via Red Hat Network. Many peoplefind this to be an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. Note that you need to select the kernel explicitly on default configurations of up2date. 5. RPMs required: Red Hat Linux 7.1: SRPMS: athlon: i386: i586: i686: Red Hat Linux 7.2: SRPMS: athlon: i386: i586: i686: Red Hat Linux 7.3: SRPMS: athlon: i386: i586: i686: Red Hat Linux 8.0: SRPMS: athlon: i386: i586: i686: 6. Verification: MD5 sum Package Name -------------------------------------------------------------------------- addeef535e3590c9c080661b6747c3a8 7.1/en/os/SRPMS/kernel-2.4.18-27.7.x.src.rpm f604974008bc2f85ddb83edcbd137f08 7.1/en/os/athlon/kernel-2.4.18-27.7.x.athlon.rpm 87298e818938d0db069030f2737a83c1 7.1/en/os/athlon/kernel-smp-2.4.18-27.7.x.athlon.rpm d8d7ad334e192989308399924cbf91f8 7.1/en/os/i386/kernel-2.4.18-27.7.x.i386.rpm 2060403022a1dc25a5700356d2d6b649 7.1/en/os/i386/kernel-BOOT-2.4.18-27.7.x.i386.rpm 02ae46618c1b001874e1330ad57f54fa 7.1/en/os/i386/kernel-doc-2.4.18-27.7.x.i386.rpm b169f55fef2064ef29c753674aaba9b0 7.1/en/os/i386/kernel-source-2.4.18-27.7.x.i386.rpm 5a970002916eebe2e6665fbbf0a44109 7.1/en/os/i586/kernel-2.4.18-27.7.x.i586.rpm b3fb5228466e86dfb9287c32b89b8118 7.1/en/os/i586/kernel-smp-2.4.18-27.7.x.i586.rpm cab59b8ce75e659243340b811a0e59ad 7.1/en/os/i686/kernel-2.4.18-27.7.x.i686.rpm 5ceca1d559294ba1dee9dcf807a0e442 7.1/en/os/i686/kernel-bigmem-2.4.18-27.7.x.i686.rpm 007688dc1826fee8abaff646ea77cedc 7.1/en/os/i686/kernel-debug-2.4.18-27.7.x.i686.rpm 53187f3f166aa6e5a500b106d6bff69c 7.1/en/os/i686/kernel-smp-2.4.18-27.7.x.i686.rpm addeef535e3590c9c080661b6747c3a87.2/en/os/SRPMS/kernel-2.4.18-27.7.x.src.rpm f604974008bc2f85ddb83edcbd137f08 7.2/en/os/athlon/kernel-2.4.18-27.7.x.athlon.rpm 87298e818938d0db069030f2737a83c1 7.2/en/os/athlon/kernel-smp-2.4.18-27.7.x.athlon.rpm d8d7ad334e192989308399924cbf91f8 7.2/en/os/i386/kernel-2.4.18-27.7.x.i386.rpm 2060403022a1dc25a5700356d2d6b649 7.2/en/os/i386/kernel-BOOT-2.4.18-27.7.x.i386.rpm 02ae46618c1b001874e1330ad57f54fa 7.2/en/os/i386/kernel-doc-2.4.18-27.7.x.i386.rpm b169f55fef2064ef29c753674aaba9b0 7.2/en/os/i386/kernel-source-2.4.18-27.7.x.i386.rpm 5a970002916eebe2e6665fbbf0a44109 7.2/en/os/i586/kernel-2.4.18-27.7.x.i586.rpm b3fb5228466e86dfb9287c32b89b8118 7.2/en/os/i586/kernel-smp-2.4.18-27.7.x.i586.rpm cab59b8ce75e659243340b811a0e59ad 7.2/en/os/i686/kernel-2.4.18-27.7.x.i686.rpm 5ceca1d559294ba1dee9dcf807a0e442 7.2/en/os/i686/kernel-bigmem-2.4.18-27.7.x.i686.rpm 007688dc1826fee8abaff646ea77cedc 7.2/en/os/i686/kernel-debug-2.4.18-27.7.x.i686.rpm 53187f3f166aa6e5a500b106d6bff69c 7.2/en/os/i686/kernel-smp-2.4.18-27.7.x.i686.rpm addeef535e3590c9c080661b6747c3a8 7.3/en/os/SRPMS/kernel-2.4.18-27.7.x.src.rpm f604974008bc2f85ddb83edcbd137f08 7.3/en/os/athlon/kernel-2.4.18-27.7.x.athlon.rpm 87298e818938d0db069030f2737a83c1 7.3/en/os/athlon/kernel-smp-2.4.18-27.7.x.athlon.rpm d8d7ad334e192989308399924cbf91f8 7.3/en/os/i386/kernel-2.4.18-27.7.x.i386.rpm 2060403022a1dc25a5700356d2d6b649 7.3/en/os/i386/kernel-BOOT-2.4.18-27.7.x.i386.rpm 02ae46618c1b001874e1330ad57f54fa 7.3/en/os/i386/kernel-doc-2.4.18-27.7.x.i386.rpm b169f55fef2064ef29c753674aaba9b0 7.3/en/os/i386/kernel-source-2.4.18-27.7.x.i386.rpm 5a970002916eebe2e6665fbbf0a44109 7.3/en/os/i586/kernel-2.4.18-27.7.x.i586.rpm b3fb5228466e86dfb9287c32b89b8118 7.3/en/os/i586/kernel-smp-2.4.18-27.7.x.i586.rpm cab59b8ce75e659243340b811a0e59ad 7.3/en/os/i686/kernel-2.4.18-27.7.x.i686.rpm 5ceca1d559294ba1dee9dcf807a0e442 7.3/en/os/i686/kernel-bigmem-2.4.18-27.7.x.i686.rpm 007688dc1826fee8abaff646ea77cedc 7.3/en/os/i686/kernel-debug-2.4.18-27.7.x.i686.rpm 53187f3f166aa6e5a500b106d6bff69c7.3/en/os/i686/kernel-smp-2.4.18-27.7.x.i686.rpm 1eca60a3b18951dc74a0d4e59eafea69 8.0/en/os/SRPMS/kernel-2.4.18-27.8.0.src.rpm 097df4f27af2703a8332d136b6a87db4 8.0/en/os/athlon/kernel-2.4.18-27.8.0.athlon.rpm 5ecb81df3091f5fec327d789643b973d 8.0/en/os/athlon/kernel-smp-2.4.18-27.8.0.athlon.rpm 05152635e760b2f15b21e343da99ddf4 8.0/en/os/i386/kernel-2.4.18-27.8.0.i386.rpm 2c737942e4ea911d58b87fcc5a22eece 8.0/en/os/i386/kernel-BOOT-2.4.18-27.8.0.i386.rpm 0d45350f1bc10a45698ca517b2683869 8.0/en/os/i386/kernel-doc-2.4.18-27.8.0.i386.rpm 6db233f9749ca25b3fff2073aa0afaea 8.0/en/os/i386/kernel-source-2.4.18-27.8.0.i386.rpm c6f8aba34d85c7447ab4c2c1ab90e7f2 8.0/en/os/i586/kernel-2.4.18-27.8.0.i586.rpm 80d3cff38bd8d535bbe239a5958730af 8.0/en/os/i586/kernel-smp-2.4.18-27.8.0.i586.rpm 4c0fc846e4faeab3e2e1b966aa65d945 8.0/en/os/i686/kernel-2.4.18-27.8.0.i686.rpm d138caa438cc87fc6835da69626a1602 8.0/en/os/i686/kernel-bigmem-2.4.18-27.8.0.i686.rpm ad41c60b306912c33a4b050511eec08c 8.0/en/os/i686/kernel-debug-2.4.18-27.8.0.i686.rpm c5e17489cee52cd526ebac66604a22ba 8.0/en/os/i686/kernel-smp-2.4.18-27.8.0.i686.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at About You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2003-0127 8. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: `. ` --------------------------------------------------------------------- Red Hat Security Advisory Sy. packages, updated, kernel, linux, these. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.