USN-7968-1

Source
https://ubuntu.com/security/notices/USN-7968-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7968-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7968-1
Upstream
Published
2026-01-19T14:59:49.583551Z
Modified
2026-01-20T16:30:53.528932Z
Summary
apache2 vulnerabilities
Details

It was discovered that the Apache HTTP Server incorrectly handled failed ACME certificate renewals. This could result in renewal attempts to be repeated without delays, possibly leading to a denial of service. (CVE-2025-55753)

Anthony Parfenov discovered that the Apache HTTP Server would pass the query string to cmd directives when configured with Server Side Includes (SSI) enabled and mod_cgid. An attacker could possibly use this issue to execute arbitrary code. (CVE-2025-58098)

Mattias Åsander discovered that the Apache HTTP Server incorrectly neutralized certain environment variables. This could result in unexpectedly superseding variables calculated by the server for CGI programs. (CVE-2025-65082)

Mattias Åsander discovered that the Apache HTTP Server incorrectly handled AllowOverride FileInfo configurations when using mod_userdir with suexec. An attacker with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. (CVE-2025-66200)

References

Affected packages

Ubuntu:22.04:LTS / apache2

Package

Name
apache2
Purl
pkg:deb/ubuntu/apache2@2.4.52-1ubuntu4.18?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.52-1ubuntu4.18

Affected versions

2.*

2.4.48-3.1ubuntu3
2.4.48-3.1ubuntu4
2.4.51-2ubuntu1
2.4.52-1ubuntu1
2.4.52-1ubuntu2
2.4.52-1ubuntu4
2.4.52-1ubuntu4.1
2.4.52-1ubuntu4.2
2.4.52-1ubuntu4.3
2.4.52-1ubuntu4.4
2.4.52-1ubuntu4.5
2.4.52-1ubuntu4.6
2.4.52-1ubuntu4.7
2.4.52-1ubuntu4.8
2.4.52-1ubuntu4.9
2.4.52-1ubuntu4.10
2.4.52-1ubuntu4.11
2.4.52-1ubuntu4.12
2.4.52-1ubuntu4.13
2.4.52-1ubuntu4.14
2.4.52-1ubuntu4.15
2.4.52-1ubuntu4.16

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "apache2",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-bin",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-data",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-dev",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-ssl-dev",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-suexec-custom",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-suexec-pristine",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "apache2-utils",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "libapache2-mod-md",
            "binary_version": "2.4.52-1ubuntu4.18"
        },
        {
            "binary_name": "libapache2-mod-proxy-uwsgi",
            "binary_version": "2.4.52-1ubuntu4.18"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7968-1.json"

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-55753"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58098"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-65082"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-66200"
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}

Ubuntu:24.04:LTS / apache2

Package

Name
apache2
Purl
pkg:deb/ubuntu/apache2@2.4.58-1ubuntu8.10?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.58-1ubuntu8.10

Affected versions

2.*

2.4.57-2ubuntu2
2.4.57-2ubuntu3
2.4.58-1ubuntu1
2.4.58-1ubuntu2
2.4.58-1ubuntu6
2.4.58-1ubuntu7
2.4.58-1ubuntu8
2.4.58-1ubuntu8.1
2.4.58-1ubuntu8.2
2.4.58-1ubuntu8.3
2.4.58-1ubuntu8.4
2.4.58-1ubuntu8.5
2.4.58-1ubuntu8.6
2.4.58-1ubuntu8.7
2.4.58-1ubuntu8.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "apache2",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-bin",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-data",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-dev",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-ssl-dev",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-suexec-custom",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-suexec-pristine",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "apache2-utils",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "libapache2-mod-md",
            "binary_version": "2.4.58-1ubuntu8.10"
        },
        {
            "binary_name": "libapache2-mod-proxy-uwsgi",
            "binary_version": "2.4.58-1ubuntu8.10"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7968-1.json"

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-55753"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58098"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-65082"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-66200"
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}

Ubuntu:25.10 / apache2

Package

Name
apache2
Purl
pkg:deb/ubuntu/apache2@2.4.64-1ubuntu3.2?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.64-1ubuntu3.2

Affected versions

2.*

2.4.63-1ubuntu1
2.4.63-1ubuntu3
2.4.64-1ubuntu2
2.4.64-1ubuntu3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "apache2",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-bin",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-data",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-dev",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-ssl-dev",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-suexec-custom",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-suexec-pristine",
            "binary_version": "2.4.64-1ubuntu3.2"
        },
        {
            "binary_name": "apache2-utils",
            "binary_version": "2.4.64-1ubuntu3.2"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7968-1.json"

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-55753"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58098"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
                },
                {
                    "type": "Ubuntu",
                    "score": "low"
                }
            ],
            "id": "CVE-2025-65082"
        },
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-66200"
        }
    ],
    "ecosystem": "Ubuntu:25.10"
}