Home / mailingsPDF  

[USN-8898-1] Apache HTTP Server vulnerabilities

Posted on 08 October 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8898-1
October 07, 2026

apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Apache HTTP Server.

Software Description:
- apache2: Apache HTTP server

Details:

It was discovered that Apache HTTP Server's mod_rewrite module incorrectly
handled memory when performing certain variable lookups. A remote attacker
could possibly use this issue to cause a denial of service or execute
arbitrary code. (CVE-2026-56154)

Lucian Nitescu, Simon Kappel, and Gianluca Danesin discovered that Apache
HTTP Server's mod_http2 module incorrectly handled memory when processing
certain HTTP/2 connections. A remote attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. This issue only
affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 26.04 LTS. (CVE-2026-57941)

Juthawong Naisanguansee, Charles Vosburgh, Mike Read, and Ryoma Nishioka
discovered that Apache HTTP Server's mod_ssl module incorrectly handled
certain expressions. An attacker could possibly use this issue to bypass
intended access restrictions. (CVE-2026-59797)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
apache2 2.4.66-2ubuntu2.5
apache2-bin 2.4.66-2ubuntu2.5
apache2-dev 2.4.66-2ubuntu2.5
apache2-ssl-dev 2.4.66-2ubuntu2.5
apache2-suexec-custom 2.4.66-2ubuntu2.5
apache2-suexec-pristine 2.4.66-2ubuntu2.5
apache2-utils 2.4.66-2ubuntu2.5

Ubuntu 24.04 LTS
apache2 2.4.58-1ubuntu8.16
apache2-bin 2.4.58-1ubuntu8.16
apache2-dev 2.4.58-1ubuntu8.16
apache2-ssl-dev 2.4.58-1ubuntu8.16
apache2-suexec-custom 2.4.58-1ubuntu8.16
apache2-suexec-pristine 2.4.58-1ubuntu8.16
apache2-utils 2.4.58-1ubuntu8.16
libapache2-mod-md 2.4.58-1ubuntu8.16
libapache2-mod-proxy-uwsgi 2.4.58-1ubuntu8.16

Ubuntu 22.04 LTS
apache2 2.4.52-1ubuntu4.24
apache2-bin 2.4.52-1ubuntu4.24
apache2-dev 2.4.52-1ubuntu4.24
apache2-ssl-dev 2.4.52-1ubuntu4.24
apache2-suexec-custom 2.4.52-1ubuntu4.24
apache2-suexec-pristine 2.4.52-1ubuntu4.24
apache2-utils 2.4.52-1ubuntu4.24
libapache2-mod-md 2.4.52-1ubuntu4.24
libapache2-mod-proxy-uwsgi 2.4.52-1ubuntu4.24

Ubuntu 20.04 LTS
apache2 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
apache2-bin 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
apache2-dev 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
apache2-ssl-dev 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
apache2-suexec-custom 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
apache2-utils 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
libapache2-mod-md 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro
libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm8
Available with Ubuntu Pro

Ubuntu 18.04 LTS
apache2 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro
apache2-bin 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro
apache2-dev 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro
apache2-ssl-dev 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro
apache2-suexec-custom 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro
apache2-utils 2.4.29-1ubuntu4.27+esm12
Available with Ubuntu Pro

Ubuntu 16.04 LTS
apache2 2.4.18-2ubuntu3.17+esm21
Available with Ubuntu Pro
apache2-bin 2.4.18-2ubuntu3.17+esm21
Available with Ubuntu Pro
apache2-dev 2.4.18-2ubuntu3.17+esm21
Available with Ubuntu Pro
apache2-suexec-custom 2.4.18-2ubuntu3.17+esm21
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.18-2ubuntu3.17+esm21
Available with Ubuntu Pro
apache2-utils 2.4.18-2ubuntu3.17+esm21
Available with Ubuntu Pro

Ubuntu 14.04 LTS
apache2 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-bin 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-dev 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-mpm-event 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-mpm-itk 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-mpm-prefork 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-mpm-worker 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-suexec 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-suexec-custom 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2-utils 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
apache2.2-bin 2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
libapache2-mod-macro 1:2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro
libapache2-mod-proxy-html 1:2.4.7-1ubuntu4.22+esm16
Available with Ubuntu Pro

After a standard system update you need to restart apache2 to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8898-1
CVE-2026-56154, CVE-2026-57941, CVE-2026-59797

Package Information:
https://launchpad.net/ubuntu/+source/apache2/2.4.66-2ubuntu2.5
https://launchpad.net/ubuntu/+source/apache2/2.4.58-1ubuntu8.16
https://launchpad.net/ubuntu/+source/apache2/2.4.52-1ubuntu4.24

--===============4859104699295324732==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP