Linuxsecurity
Critical Vulnerabilities Found in APR-util Affecting Multiple Ubuntu Versions
Article Content
On September 3, 2026, Ubuntu released USN-8719-1, detailing several security vulnerabilities in APR-util. The vulnerabilities include improper password hash comparisons (CVE-2025-49506), recursive XML element quoting issues (CVE-2026-32327), and heap-based buffer overflows in the Redis (CVE-2026-34501) and memcached clients (CVE-2026-34502). These flaws could lead to sensitive information disclosure, application crashes, or arbitrary code execution. Affected systems include Ubuntu 18.04, 20.04, 22.04, 24.04, and 26.04 LTS. The vulnerabilities were published on August 6, 2026, and require immediate patching to mitigate risks. Administrators are advised to update their systems to the latest package versions to address these issues.
Key Points: • Multiple critical vulnerabilities found in APR-util affecting several Ubuntu LTS versions. • CVE-2025-49506 allows potential sensitive information disclosure due to improper hash comparisons. • Heap-based buffer overflows could lead to application crashes or arbitrary code execution.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.