Back Linuxsecurity Ubuntu 20.04 Apache2 Denial of Service & Info Disclosure USN-8571
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
USN-8571-1 introduced a regression in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was incomplete due to a missing library symbol, resulting in a regression that could cause Apache HTTP Server to fail to start when HTTP/2 proxying was enabled. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_authn_socache. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33007) Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache HTTP Server had an HTTP response splitting vulnerability in multiple modules when used with untrusted or compromised backend servers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-33523) Elhanan H... Read the Full Advisory
USN-8571-1 introduced a regression in Apache HTTP Server.
Software Description:
- apache2: Apache HTTP server
USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was
incomplete due to a missing library symbol, resulting in a regression
that could cause Apache HTTP Server to fail to start when HTTP/2
proxying was enabled. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server
incorrectly handled certain memory operations in mod_authn_socache. A
remote attacker could possibly use this issue to cause a denial of service.
Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache
HTTP Server had an HTTP response splitting vulnerability in multiple
modules when used with untrusted or compromised backend servers. An
attacker could possibly use this issue to inject arbitrary HTTP headers.
The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS apache2 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-bin 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-data 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-dev 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-ssl-dev 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-suexec-custom 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-utils 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro libapache2-mod-md 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
Ubuntu Security Notice USN-8571-2
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
