Skip to content
Ubuntu 26.04 APR-util Important Heap Overflow DoS USN-8719

Ubuntu 26.04 APR-util Important Heap Overflow DoS USN-8719

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

Several security issues were fixed in APR-util. Software Description: - apr-util: Apache Portable Runtime Utility Library Details: It was discovered that APR-util incorrectly performed password hash comparisons in a way that was not constant-time. An attacker could possibly use this issue to obtain sensitive information. (CVE-2025-49506) It was discovered that APR-util incorrectly handled recursive XML element quoting. An attacker could possibly use this issue to cause applications using APR-util to crash, resulting in a denial of service. (CVE-2026-32327) It was discovered that the APR-util Redis client incorrectly handled certain network data, resulting in a heap-based buffer overflow. A remote attacker could possibly use this issue to cause APR-util applications to crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-34501) It was discovered that the APR-util memcac... Read the Full Advisory

Several security issues were fixed in APR-util.

Software Description:

- apr-util: Apache Portable Runtime Utility Library

It was discovered that APR-util incorrectly performed password hash

comparisons in a way that was not constant-time.

An attacker could possibly use this issue to obtain sensitive information.

It was discovered that APR-util incorrectly handled recursive XML element

quoting. An attacker could possibly use this issue to cause applications

using APR-util to crash, resulting in a denial of service.

It was discovered that the APR-util Redis client incorrectly handled

certain network data, resulting in a heap-based buffer overflow. A remote

attacker could possibly use this issue to cause APR-util applications to

crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,

Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.

It was discovered that the APR-util memcac...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libaprutil1t64 1.6.3-3ubuntu3.1 Ubuntu 24.04 LTS libaprutil1t64 1.6.3-1.1ubuntu7.1 Ubuntu 22.04 LTS libaprutil1 1.6.1-5ubuntu4.22.04.3 Ubuntu 20.04 LTS libaprutil1 1.6.1-4ubuntu2.2+esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS libaprutil1 1.6.1-2ubuntu0.1+esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS libaprutil1 1.5.4-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 14.04 LTS libaprutil1 1.5.3-1ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2025-49506, CVE-2026-32327, CVE-2026-34501, CVE-2026-34502

Ubuntu Security Notice USN-8719-1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases

Extracted Entities