[CLSA-2026:1787222082] Fix CVE(s): CVE-2025-49630
Type:
security
Severity:
Important
Release date:
2026-08-20 10:34:51 UTC
Description:
* SECURITY UPDATE: DoS in mod_proxy_http2 via missing Host header with ProxyPreserveHost - debian/patches/CVE-2025-49630.patch: in open_stream() in modules/http2/h2_proxy_session.c, when preserve_host is on and the client request has no Host header, fall back to r->server->server_hostname and add it to the request headers so a NULL authority no longer trips an assertion in the h2 proxy path. Backported from httpd commit 88304321841a2fe8bd5eacc70e69418b0b545ca5 (SVN r1927044, 2.4.x branch), plus adapted regression test from SVN r1934478 (test/modules/http2/test_600_h2proxy.py). - CVE-2025-49630
CVEs fixed:
Updated packages:
  • apache2_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:60ed3a4d5305b2cb42df3e9604dd3299c03fc4f2
  • apache2-bin_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:80b16c5713bf5c7e9d0d4b7ae3b4f1334735b0c8
  • apache2-data_2.4.41-4ubuntu3.23+tuxcare.els14_all.deb
    sha:45744af9945ffdcc6062b6f8e32051c8b8089fe9
  • apache2-dev_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:204b48f9d697f063ee01fba101ba8ba352663bc6
  • apache2-doc_2.4.41-4ubuntu3.23+tuxcare.els14_all.deb
    sha:147d785aebbd52d9a8c0569ffb467020269c84e0
  • apache2-ssl-dev_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:bef7e19aded022fa63c5f1e4d3c1d6fd02475df3
  • apache2-suexec-custom_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:17efd7e5e27ef21698e70951f07a27b0829b3c00
  • apache2-suexec-pristine_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:5a640c1f32dd0a6a333a091a6be90a5e87d194fc
  • apache2-utils_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:81b67e2f2a999b114c08463c1619cf099d735272
  • libapache2-mod-md_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:3e501aec42e89fa74a227adba5421d4f13bc5527
  • libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
    sha:7e04d27095373bc7d9bbbc91fe2baeb1d3a485c9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.