RHSA-2026:2995HighCVSS 9.8
Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.62 SP3 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2025-9230 — openssl: Out-of-bounds read & write in RFC 3211 KEK Unwrap CVE-2025-15467 — openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing CVE-2025-55753 — mod_md: Apache HTTP Server: mod_md (ACME), unintended retry intervals CVE-2025-58098 — httpd: Apache HTTP Server: Server Side Includes adds query string to #exec cmd=... CVE-2025-65082 — httpd: Apache HTTP Server: CGI environment variable override CVE-2025-66200 — httpd: Apache HTTP Server: mod_userdir+suexec bypass via AllowOverride FileInfo CVE-2025-69419 — openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:2995
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://docs.redhat.com/en/documentation/red_hat_jboss_core_services/2.4.62/html/red_hat_jboss_core_services_apache_http_server_2.4.62_service_pack_3_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2396054
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419140
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419262
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2430386
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_2995.json