Back to Security Advisories
High 2026-07-22

Httpd:2.4 Security Update — AlmaLinux 8 (ALSA-2026:42828)

AlmaLinux 8

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server. Security Fix(es): * httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516) * httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169) * httpd: Apache HTTP Server: Heap-based Buffe…

Affected Versions

2.4

The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffe…

Type:
security

Severity:
important

Release date:
2026-07-22

Description:
The httpd packages provide the Apache HTTP Server, a powerful, efficient, and extensible web server.

Security Fix(es):

* httpd: incomplete fix for CVE-2023-38709 (CVE-2024-42516)
* httpd: NULL pointer dereference via specially crafted request (CVE-2026-29169)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers (CVE-2026-34356)
* httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server (CVE-2026-44185)
* httpd: Apache HTTP Server: Denial of Service via crafted regular expressions (CVE-2026-44631)
* httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server (CVE-2026-44186)
* httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc (CVE-2026-42536)
* httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass (CVE-2026-34355)
* httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime (CVE-2026-43951)

Bug Fix(es) and Enhancement(s):

* mod_proxy_html regression in CVE-2026-34355 fix [almalinux-8.10.z] (JIRA:AlmaLinux-192751)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 httpd-tools-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm 09f6d0972f5c781532532c5e65c122c3135cf6f5debf199e629380b8629093f7
aarch64 mod_ldap-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm 4048b535ab4075a78099df1fc3f3da02ffd6ef395917b1db0af9b4b47a4151e9
aarch64 mod_proxy_html-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm 5b3b165670c84e76d26a6338e2f13b9324edbc7410064103cce30aa3467f1a85
aarch64 httpd-devel-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm 5db259253f1564b343454f3a93096323a7c7a4bbdd270d3f371f8ccb8c1795cb
aarch64 httpd-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm 613a2760cacfcbfa0fa75ea625ae7a2001d0fa9979d02fd484a44708091344d0
aarch64 mod_ssl-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm 6f80c83954e38bee4416d5807d71d5c1864fb7752d6862e31b8e587d1e6e9f83
aarch64 mod_md-2.0.8-8.module_el8.10.0+4088+57f011c1.2.aarch64.rpm 9089a727d04e9e8a6e719c4980ccb7e179a95a0ceda7ac2d69ab335ae0179cd6
aarch64 mod_http2-1.15.7-10.module_el8.10.0+4233+8b7d9181.7.aarch64.rpm b1868165fc35b625d6662669a07f3ed91e485c5f3bc62b3f013ad4758ef7862a
aarch64 mod_session-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.aarch64.rpm f0d3207c5c7aa3808c83e3c83bfe6c51506d82526ef644dced009996b5e08925
noarch httpd-manual-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.noarch.rpm d963250fcc124df89e4fa1c92d752f600ccc0d9201b8ddb1dc565eaf221908ff
ppc64le httpd-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm 01d14c8e330b116eece4b032eae236ea5216d1f887e8e72402a968a8a4eae9f5
ppc64le mod_ssl-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm 491cb7e706c428564b03ab86b20721dd0b2390cf141abf92f152b4dd59275e17
ppc64le mod_http2-1.15.7-10.module_el8.10.0+4233+8b7d9181.7.ppc64le.rpm 4a900481c319467ddffa19ce6c06d1283471badaf2abf6167d118547aacb0472
ppc64le httpd-devel-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm 4ae57b748a0d0cc38f0937abf2c36d5687a6852db8fa80e53044cc574d650235
ppc64le mod_session-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm a24c5c5cfc577ef5a5c9476ce275d20035ce328290198f3724d2b45a5679f0af
ppc64le mod_ldap-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm a6cacd02154f8f4b231bec20471bd6dc281a2b7117277a9186463b132beca567
ppc64le mod_md-2.0.8-8.module_el8.10.0+4088+57f011c1.2.ppc64le.rpm ac86f2bf2070a4ae5307d7aa7c99e85dcd02bc0d293c25de3fb8d2a13263e338
ppc64le httpd-tools-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm cf03973c513f59c8b94a7a1ea7beefe471d324cf4be9b4b34dc3f3f4702db214
ppc64le mod_proxy_html-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.ppc64le.rpm e54227bddcbe62354261031525880203702b7ac777332c4177e22f565a5e1565
s390x httpd-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm 453dc98f84d2d3df3900907bde7101ea08cbdab946ce1e5435d477af220319ec
s390x mod_md-2.0.8-8.module_el8.10.0+4088+57f011c1.2.s390x.rpm 51f08f5a2c2c9925c2d8acf5069e109f519302af55ab044dba7de03782591748
s390x httpd-devel-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm 53376634d276e947d8ae10cd100a82be6887dc2a44045054177e393c9cd3029a
s390x mod_session-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm 66d1bd00ad80a68a5d7557570aca613909fe1b9b656a1190f8c84f2a0eae6740
s390x httpd-tools-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm 6dab375ae66b41a65c1b29735f800e262a7ac787d7e8c416d317bc137688d031
s390x mod_proxy_html-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm 6f5a8e63f584fbb9dbfe351dbcb1240ef2f5ee1c0cc8ca9727bd17a3168c0a83
s390x mod_ldap-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm cd6d5d1688bea33bf3f81980a25caaa6d2369c3f16c832bba545e038a330e914
s390x mod_ssl-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.s390x.rpm f6e3ce0a479eb7be70c32c0bdb255454e243d727d65efcf98d0e877af4eddd63
s390x mod_http2-1.15.7-10.module_el8.10.0+4233+8b7d9181.7.s390x.rpm ff47e1fb2a585ec374a56215d22828192bddf16403b007260955c8e1649e8fdb
x86_64 mod_md-2.0.8-8.module_el8.10.0+4088+57f011c1.2.x86_64.rpm 035593075bacc46bb0e52d950bb12cb5cc30744e23799cb27f1962d697ba7e9e
x86_64 mod_ldap-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm 4148bf8dd72c4bf7aaa4e8de6049ef7e5d10dca2302eb8ca711b12007f76f644
x86_64 mod_http2-1.15.7-10.module_el8.10.0+4233+8b7d9181.7.x86_64.rpm 4beca8f6509a21445730a1fcf074335d374eaf3f5dcd6d6152c2bcd0c9f6d9fd
x86_64 mod_proxy_html-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm 7d93159593c36599df90f2ecb7ff1f3f27067b44dd770ab12686bff70cead39d
x86_64 mod_session-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm 85d719fe57529e6cfc1d30b34744412431d690164221833e9d95affb5e35eef4
x86_64 httpd-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm 8bfb26bc6fd3dd252a48b200fcee4ab23854e19de9e206ab65430628db5d133b
x86_64 httpd-devel-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm c663287adb0988b2d52a30dae52916d072e980562b7d6558b9030c0862508081
x86_64 httpd-tools-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm cd403fe9f1a5cbf8f7a079ea60b2a5f6d1b6f2714602841f59a4e0522bc5ae26
x86_64 mod_ssl-2.4.37-65.module_el8.10.0+4233+8b7d9181.9.x86_64.rpm f4b5040c79fc5c93be06d01d9182c380c78574b7af1bea256ccc882e0260076d

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Check Your System