Skip to content
Mageia 10 9 apr-util Security Update CVE-2025-49506 CVE-2026

Mageia 10 9 apr-util Security Update CVE-2025-49506 CVE-2026

Linuxsecurity LinuxSecurity Advisories September 2, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Description: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502)

Description: Apache Portable Runtime Utility: apr_password_validate() vulnerable to timing attack. (CVE-2025-49506) Apache Portable Runtime Utility: apr-util XML stack recursion crash. (CVE-2026-32327) Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle. (CVE-2026-34191) Apache Portable Runtime Utility: Heap buffer overflow in APR redis client. (CVE-2026-34501) Apache Portable Runtime Utility: Heap buffer overflow in APR memcached client. (CVE-2026-34502)

- - - - - - - -

-

-

-

-

-

-

-

-

- 10/core/apr-util-1.6.3-3.1.mga10 - 9/core/apr-util-1.6.3-1.1.mga9

- 10/core/apr-util-1.6.3-3.1.mga10

- 9/core/apr-util-1.6.3-1.1.mga9

Publication date: 02 Sep 2026 URL: https: //advisories.mageia.org/MGASA-2026-0364.html Type: security CVE: CVE-2025-49506, CVE-2026-32327, CVE-2026-34191, CVE-2026-34501, CVE-2026-34502

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases