Skip to content
Ubuntu Apache2 Critical Denial of Service Threats USN-8516

Ubuntu Apache2 Critical Denial of Service Threats USN-8516

Linuxsecurity LinuxSecurity Advisories July 8, 2026

Several security issues were fixed in Apache HTTP Server. Software Description: - apache2: Apache HTTP server Details: It was discovered that Apache HTTP Server's mod_ldap module incorrectly handled memory when processing per-directory configurations. An attacker could use this issue to cause the server to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-29167) It was discovered that Apache HTTP Server's mod_proxy_ftp module incorrectly handled HTML generation for FTP directory listings. A remote attacker could possibly use this issue to inject arbitrary web script or HTML. (CVE-2026-29170) It was discovered that Apache HTTP Server's mod_proxy_html module incorrectly handled certain content from an untrusted backend. A remote attacker could possibly use this issue to cause Apache HTTP Server to crash, resulting in a denial of service. (CVE-2026-34355) It was discovered that Apache HTTP Server incorrectly handled ProxyPassReverseCookie dir... Read the Full Advisory

Several security issues were fixed in Apache HTTP Server.

Software Description:

- apache2: Apache HTTP server

It was discovered that Apache HTTP Server's mod_ldap module incorrectly

handled memory when processing per-directory configurations. An attacker

could use this issue to cause the server to crash, resulting in a denial of

service, or possibly execute arbitrary code. (CVE-2026-29167)

It was discovered that Apache HTTP Server's mod_proxy_ftp module

incorrectly handled HTML generation for FTP directory listings. A remote

attacker could possibly use this issue to inject arbitrary web script or

HTML. (CVE-2026-29170)

It was discovered that Apache HTTP Server's mod_proxy_html module

incorrectly handled certain content from an untrusted backend. A remote

attacker could possibly use this issue to cause Apache HTTP Server to

crash, resulting in a denial of service. (CVE-2026-34355)

It was discovered that Apache HTTP Server incorrectly handled

ProxyPassReverseCookie dir...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS apache2 2.4.66-2ubuntu2.4 Ubuntu 24.04 LTS apache2 2.4.58-1ubuntu8.15 Ubuntu 22.04 LTS apache2 2.4.52-1ubuntu4.23 In general, a standard system update will make all the necessary changes.

CVE-2026-29167, CVE-2026-29170, CVE-2026-34355, CVE-2026-34356,

CVE-2026-42535, CVE-2026-42536, CVE-2026-43951, CVE-2026-44119,

CVE-2026-44185, CVE-2026-44186, CVE-2026-44631, CVE-2026-48913

Ubuntu Security Notice USN-8516-1

Get the latest Linux and open source security news straight to your inbox.