Home / mailingsPDF  

[USN-8589-1] Apache HTTP Server vulnerabilities

Posted on 22 July 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8589-1
July 22, 2026

apache2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Apache HTTP Server.

Software Description:
- apache2: Apache HTTP server

Details:

It was discovered that Apache HTTP Server's mod_ldap module incorrectly
handled memory when processing per-directory configurations. A remote
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2026-29167)

It was discovered that Apache HTTP Server's mod_proxy_ftp module
incorrectly handled HTML generation for FTP directory listings. A remote
attacker could possibly use this issue to inject arbitrary web script or
HTML. (CVE-2026-29170)

Nitescu Lucian discovered that Apache HTTP Server's mod_auth_digest module
was vulnerable to a timing attack. A remote attacker could possibly use
this issue to bypass Digest authentication. (CVE-2026-33006)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
apache2 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-bin 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-dev 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-ssl-dev 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-suexec-custom 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
apache2-utils 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
libapache2-mod-md 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro
libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm6
Available with Ubuntu Pro

Ubuntu 18.04 LTS
apache2 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-bin 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-dev 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-ssl-dev 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-suexec-custom 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro
apache2-utils 2.4.29-1ubuntu4.27+esm11
Available with Ubuntu Pro

Ubuntu 16.04 LTS
apache2 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-bin 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-dev 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-suexec-custom 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro
apache2-utils 2.4.18-2ubuntu3.17+esm20
Available with Ubuntu Pro

Ubuntu 14.04 LTS
apache2 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-bin 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-dev 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-event 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-itk 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-prefork 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-mpm-worker 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-suexec 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-suexec-custom 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-suexec-pristine 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2-utils 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
apache2.2-bin 2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
libapache2-mod-macro 1:2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro
libapache2-mod-proxy-html 1:2.4.7-1ubuntu4.22+esm15
Available with Ubuntu Pro

After a standard system update you need to restart apache2 to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8589-1
CVE-2026-29167, CVE-2026-29170, CVE-2026-33006

--===============7523433864969432893==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP