Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (13)
📋 Description
CVE-2026-29167 — httpd: Apache HTTP Server: Arbitrary code execution or denial of service via use-after-free in mod_ldap per-directory configuration CVE-2026-29170 — httpd: Apache HTTP Server: Cross-site scripting in mod_proxy_ftp via HTML directory list generation CVE-2026-34355 — httpd: Apache HTTP Server: Buffer overflow in mod_proxy_html allows security bypass CVE-2026-34356 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via malicious backend servers CVE-2026-42535 — httpd: Apache httpd mod_dav_fs: Denial of Service due to path handling issue CVE-2026-42536 — httpd: Apache HTTP Server: Heap-based Buffer Overflow via untrusted content in mod_xml2enc CVE-2026-43951 — httpd: Apache HTTP Server: Out-of-bounds Read in mod_headers and mod_mime CVE-2026-44119 — httpd: Apache HTTP Server: Local .htaccess authors can read files with httpd user privileges CVE-2026-44185 — httpd: Apache HTTP Server: Buffer Over-read via outbound OCSP requests to attacker-controlled server CVE-2026-44186 — httpd: Apache HTTP Server: Denial of Service in mod_proxy_ftp via attacker-controlled FTP server CVE-2026-44631 — httpd: Apache HTTP Server: Denial of Service via crafted regular expressions CVE-2026-48913 — httpd: mod_http2: Apache HTTP Server mod_http2: Use After Free vulnerability allows arbitrary code execution or denial of service. CVE-2026-49975 — httpd: httpd: HTTP/2 Remote Denial of Service via compression bomb and Slowloris-style attack
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:25042
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-49975
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-44186
- externalhttps://access.redhat.com/security/cve/CVE-2026-44631
- externalhttps://access.redhat.com/security/cve/CVE-2026-34355
- externalhttps://access.redhat.com/security/cve/CVE-2026-34356
- externalhttps://access.redhat.com/security/cve/CVE-2026-42535
- externalhttps://access.redhat.com/security/cve/CVE-2026-42536
- externalhttps://access.redhat.com/security/cve/CVE-2026-43951
- externalhttps://access.redhat.com/security/cve/CVE-2026-48913
- externalhttps://access.redhat.com/security/cve/CVE-2026-29167
- externalhttps://access.redhat.com/security/cve/CVE-2026-44185
- externalhttps://access.redhat.com/security/cve/CVE-2026-44119
- externalhttps://access.redhat.com/security/cve/CVE-2026-29170
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25042.json