Back Linuxsecurity Mageia 10 9 apr-util Security Update CVE-2025-49506 CVE-2026
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
Description: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502)
Description: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502)
- - - - - - - -
-
-
-
-
-
-
-
-
- 10/core/apr-util-1.6.3-3.1.mga10 - 9/core/apr-util-1.6.3-1.1.mga9
- 10/core/apr-util-1.6.3-3.1.mga10
- 9/core/apr-util-1.6.3-1.1.mga9
Publication date: 02 Sep 2026 URL: https: //advisories.mageia.org/MGASA-2026-0364.html Type: security CVE: CVE-2025-49506, CVE-2026-32327, CVE-2026-34191, CVE-2026-34501, CVE-2026-34502
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
