MGASA-2026-0129

Source
https://advisories.mageia.org/MGASA-2026-0129.html
Import Source
https://advisories.mageia.org/MGASA-2026-0129.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2026-0129
Upstream
  • CVE-2026-24072
  • CVE-2026-29169
  • CVE-2026-33006
  • CVE-2026-33007
Published
2026-05-13T07:00:52Z
Modified
2026-05-13T07:16:51Z
Summary
Updated apache packages fix security vulnerabilities
Details

http2: double free and possible RCE on early reset. (CVE-2026-23918) mod_rewrite elevation of privileges via ap_expr. (CVE-2026-24072) buffer overflow in mod_proxy_ajp via ajp_msg_check_header(). (CVE-2026-28780) mod_md unrestricted OCSP response. (CVE-2026-29168) mod_dav_lock indirect lock crash. (CVE-2026-29169) mod_auth_digest timing attack. (CVE-2026-33006) mod_authn_socache crash. (CVE-2026-33007) HTTP response splitting forwarding malicious status line. (CVE-2026-33523) Off-by-one OOB reads in AJP getter functions. (CVE-2026-33857) Heap Buffer Over-Read Due to Missing Null-Termination Check (ajp_msg_get_string). (CVE-2026-34032) Heap Over-Read and memory disclosure in ajp_parse_data(). (CVE-2026-34059)

References
Credits

Affected packages

Mageia:9 / apache

Package

Name
apache
Purl
pkg:rpm/mageia/apache?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.67-1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0129.json"