[CLSA-2026:1787141541] Fix CVE(s): CVE-2026-32327, CVE-2026-34501, CVE-2026-34502
Type:
security
Severity:
Critical
Release date:
2026-08-19 12:12:33 UTC
Description:
* SECURITY UPDATE: heap buffer overflow in the memcached client - debian/patches/CVE-2026-34502.patch: validate CRLF line termination and response lengths in memcache/apr_memcache.c - CVE-2026-34502 * SECURITY UPDATE: heap buffer overflow in the redis client - debian/patches/CVE-2026-34501.patch: bound the bulk response length in redis/apr_redis.c - CVE-2026-34501 * SECURITY UPDATE: stack recursion crash on deeply nested XML - debian/patches/CVE-2026-32327.patch: limit element nesting depth in xml/apr_xml.c - CVE-2026-32327
Updated packages:
  • libaprutil1_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:37450a5b7e18f0d122cd94416ed5580c4b613784
  • libaprutil1-dbd-mysql_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:8dbf548832df5df34057c9549fe37d7f3ee1ef58
  • libaprutil1-dbd-odbc_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:2d8bc8cb609a69e2ea6cdbf4d394b8d0ce1b0293
  • libaprutil1-dbd-pgsql_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:55801ab026164d709c08cda2e5dd4b4fe4f4a5af
  • libaprutil1-dbd-sqlite3_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:a31f5186f056db4c696aed68db9fafedb47020a5
  • libaprutil1-dev_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:1f96bc0807fdba339ceb9b713a81b722e98bc50c
  • libaprutil1-ldap_1.6.1-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:51b440395a6cfb97a281d9a8d053812cf7542099
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.