Critical Vulnerabilities Found in APR-util Affecting Multiple Ubuntu Versions

Critical Vulnerabilities Found in APR-util Affecting Multiple Ubuntu Versions

First seen 3 Sep 2026, 17:39 UTC UbuntuLinuxsecurity 57.1

Article Content

Browse articles
ThreatCluster

On September 3, 2026, Ubuntu released USN-8719-1, detailing several security vulnerabilities in APR-util. The vulnerabilities include improper password hash comparisons (CVE-2025-49506), recursive XML element quoting issues (CVE-2026-32327), and heap-based buffer overflows in the Redis (CVE-2026-34501) and memcached clients (CVE-2026-34502). These flaws could lead to sensitive information disclosure, application crashes, or arbitrary code execution. Affected systems include Ubuntu 18.04, 20.04, 22.04, 24.04, and 26.04 LTS. The vulnerabilities were published on August 6, 2026, and require immediate patching to mitigate risks. Administrators are advised to update their systems to the latest package versions to address these issues.

Key Points: • Multiple critical vulnerabilities found in APR-util affecting several Ubuntu LTS versions. • CVE-2025-49506 allows potential sensitive information disclosure due to improper hash comparisons. • Heap-based buffer overflows could lead to application crashes or arbitrary code execution.

Timeline

2026-08-06
CVE-2025-49506 published
Improper password hash comparisons in APR-util could allow sensitive information disclosure.
Ubuntu
2026-08-06
CVE-2026-32327 published
Recursive XML element quoting issues could lead to denial of service in applications using APR-util.
Ubuntu
2026-08-06
CVE-2026-34501 published
Heap-based buffer overflow in the Redis client could allow remote code execution.
Ubuntu
2026-08-06
CVE-2026-34502 published
Heap-based buffer overflow in the memcached client could lead to application crashes.
Ubuntu
2026-09-03
USN-8719-1 released
Ubuntu issued a security notice detailing vulnerabilities in APR-util and urging users to patch.
Linuxsecurity