==========================================================================
Ubuntu Security Notice USN-8589-1
July 22, 2026

apache2 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Apache HTTP Server.

Software Description:
- apache2: Apache HTTP server

Details:

It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-29167)

It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)

Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module
was vulnerable to a timing attack. A remote attacker could possibly use
this issue to bypass Digest authentication. (CVE-2026-33006)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  apache2                         2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  apache2-bin                     2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  apache2-dev                     2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  apache2-ssl-dev                 2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  apache2-suexec-custom           2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  apache2-suexec-pristine         2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  apache2-utils                   2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  libapache2-mod-md               2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro
  libapache2-mod-proxy-uwsgi      2.4.41-4ubuntu3.23+esm6
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  apache2                         2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro
  apache2-bin                     2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro
  apache2-dev                     2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro
  apache2-ssl-dev                 2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro
  apache2-suexec-custom           2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro
  apache2-suexec-pristine         2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro
  apache2-utils                   2.4.29-1ubuntu4.27+esm11
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  apache2                         2.4.18-2ubuntu3.17+esm20
                                  Available with Ubuntu Pro
  apache2-bin                     2.4.18-2ubuntu3.17+esm20
                                  Available with Ubuntu Pro
  apache2-dev                     2.4.18-2ubuntu3.17+esm20
                                  Available with Ubuntu Pro
  apache2-suexec-custom           2.4.18-2ubuntu3.17+esm20
                                  Available with Ubuntu Pro
  apache2-suexec-pristine         2.4.18-2ubuntu3.17+esm20
                                  Available with Ubuntu Pro
  apache2-utils                   2.4.18-2ubuntu3.17+esm20
                                  Available with Ubuntu Pro

Ubuntu 14.04 LTS
  apache2                         2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-bin                     2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-dev                     2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-mpm-event               2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-mpm-itk                 2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-mpm-prefork             2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-mpm-worker              2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-suexec                  2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-suexec-custom           2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-suexec-pristine         2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2-utils                   2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  apache2.2-bin                   2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  libapache2-mod-macro            1:2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro
  libapache2-mod-proxy-html       1:2.4.7-1ubuntu4.22+esm15
                                  Available with Ubuntu Pro

After a standard system update you need to restart apache2 to make
all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8589-1
  CVE-2026-29167, CVE-2026-29170, CVE-2026-33006

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to