[CLSA-2026:1786481279] apr-util: Fix of 3 CVEs
Type:
security
Severity:
Critical
Release date:
2026-08-13 04:21:54 UTC
Description:
- Fix CVE-2026-34502 - heap buffer overflow in the memcached client - Fix CVE-2026-34501 - heap buffer overflow in the redis client - Fix CVE-2026-32327 - stack recursion via apr_xml_quote_elem()
Updated packages:
  • apr-util-1.6.1-23.el9.tuxcare.els1.i686.rpm
    sha:8186ba2eb34117f098375644ad59109a971499617d15dfe2251159a2e1b05a0a
  • apr-util-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:5dbed06640a8c8cb047db01be6f1110953688b4d9aa4a823324ac0c567a151cf
  • apr-util-bdb-1.6.1-23.el9.tuxcare.els1.i686.rpm
    sha:78faf7528e490a3f3467e03fb1221094d8fc752ad4b9c6de52beb4a86c8dfa5d
  • apr-util-bdb-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:d95897293dfc30ddd60bef04fcfc322c2a7098f365c269b17846a9e205e7c4e2
  • apr-util-devel-1.6.1-23.el9.tuxcare.els1.i686.rpm
    sha:20b6379806d2fded7456dccaecf4e10209ea2446b102fe76e8937fee5afed2d3
  • apr-util-devel-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:f2e60398c6aa144ee80b06c8613643c8855ff9ca5536d38723fafedfa4ac9bef
  • apr-util-ldap-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:ff655184c41c85cac4085180592dcbc5d2474204e4a99aace4469f530e97f589
  • apr-util-mysql-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:634b5c9aadb1e9a52bb6e60138c6de250ff19c218a1f37d9d1d73ec3ef32665e
  • apr-util-odbc-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:b1e3964e5d152946dc5a642105675dcbde5989af5b3f0c291c4e79219d60d191
  • apr-util-openssl-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:10ce53cade19bdaa070e6c708fafed181f6459011c9d1abca97cc179f99906a7
  • apr-util-pgsql-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:23caed2109b0a9ee418d7eafd3fae4381bb3413c169d2c3610a50df4bcfa5e66
  • apr-util-sqlite-1.6.1-23.el9.tuxcare.els1.x86_64.rpm
    sha:e89d15d321919fe82b51701cf414e115f56a030ac59e38725770d7fdf2b5a7fd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.