Skip to content
Ubuntu 20.04 Apache2 Denial of Service & Info Disclosure USN-8571

Ubuntu 20.04 Apache2 Denial of Service & Info Disclosure USN-8571

Linuxsecurity LinuxSecurity Advisories September 11, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

USN-8571-1 introduced a regression in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was incomplete due to a missing library symbol, resulting in a regression that could cause Apache HTTP Server to fail to start when HTTP/2 proxying was enabled. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_authn_socache. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33007) Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache HTTP Server had an HTTP response splitting vulnerability in multiple modules when used with untrusted or compromised backend servers. An attacker could possibly use this issue to inject arbitrary HTTP headers. (CVE-2026-33523) Elhanan H... Read the Full Advisory

USN-8571-1 introduced a regression in Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was

incomplete due to a missing library symbol, resulting in a regression

that could cause Apache HTTP Server to fail to start when HTTP/2

proxying was enabled. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server

incorrectly handled certain memory operations in mod_authn_socache. A

remote attacker could possibly use this issue to cause a denial of service.

Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache

HTTP Server had an HTTP response splitting vulnerability in multiple

modules when used with untrusted or compromised backend servers. An

attacker could possibly use this issue to inject arbitrary HTTP headers.

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS apache2 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-bin 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-data 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-dev 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-ssl-dev 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-suexec-custom 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-suexec-pristine 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro apache2-utils 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro libapache2-mod-md 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro libapache2-mod-proxy-uwsgi 2.4.41-4ubuntu3.23+esm7 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8571-2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities