[CLSA-2026:1786623875] apr-util: Fix of CVE-2025-49506
Type:
security
Severity:
Low
Release date:
2026-08-13 12:24:46 UTC
Description:
- Fix CVE-2025-49506 - non-constant-time password/hash comparison in apr_password_validate()
CVEs fixed:
Updated packages:
  • apr-util-1.6.1-23.el9.tuxcare.els2.i686.rpm
    sha:86353287fe6a0d55d4c8e39b5ccf1d21deeac7c85ead3f33364cdfb50701c18a
  • apr-util-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:9963fe704999b6aaa313d4e6d5c818e5966d5a5bac25de724e9b5c536398e917
  • apr-util-bdb-1.6.1-23.el9.tuxcare.els2.i686.rpm
    sha:cc0646e109818d9ddbc3a2e67beb13ba0e10dcd0963913813a5b6449d3de8d2a
  • apr-util-bdb-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:b7ce1f1f91430239d3ea84cfb9f04ae0f852d156e159c48f3faa9e503fe0dbee
  • apr-util-devel-1.6.1-23.el9.tuxcare.els2.i686.rpm
    sha:7f0ca98d7a5d26f9ee4a4f4d52643c2eeb2d16599261ca0c2852626b3ff3b92e
  • apr-util-devel-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:6b2b44e74ed7e8bc54ee8fbad5b578bb0a4c02b23fa91d99d1fa8e6c00002bdb
  • apr-util-ldap-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:5e6c7f7173c5ba090662832c42b0e56c63e3ce2c833f2da50bf64d2baafffea4
  • apr-util-mysql-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:d93479719b2425b7ed252c45fb162ee713a60c8a10c1591b80733f716198a8d8
  • apr-util-odbc-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:59fb6e8847fda375814a2b09005f62ebdad8a6a48a8df9193b9a9f76d063c853
  • apr-util-openssl-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:7163eb80b9dc17ccbebaa8ca4cfeb99a5c281a5f151e35c62f02cfd39ccf9fd5
  • apr-util-pgsql-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:7ef077c80c1798d46553934bf9a6f62f14dc567ac885f09294eef4e8a2ae63e6
  • apr-util-sqlite-1.6.1-23.el9.tuxcare.els2.x86_64.rpm
    sha:2122d123bccd8d88909b767b7fbd5c015d1f65784378dc2ad6692a82c6b008dd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.