Release date:
2026-08-20 10:34:51 UTC
Description:
* SECURITY UPDATE: DoS in mod_proxy_http2 via missing Host header
with ProxyPreserveHost
- debian/patches/CVE-2025-49630.patch: in open_stream() in
modules/http2/h2_proxy_session.c, when preserve_host is on and the
client request has no Host header, fall back to
r->server->server_hostname and add it to the request headers so a
NULL authority no longer trips an assertion in the h2 proxy path.
Backported from httpd commit 88304321841a2fe8bd5eacc70e69418b0b545ca5
(SVN r1927044, 2.4.x branch), plus adapted regression test from
SVN r1934478 (test/modules/http2/test_600_h2proxy.py).
- CVE-2025-49630
Updated packages:
-
apache2_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:60ed3a4d5305b2cb42df3e9604dd3299c03fc4f2
-
apache2-bin_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:80b16c5713bf5c7e9d0d4b7ae3b4f1334735b0c8
-
apache2-data_2.4.41-4ubuntu3.23+tuxcare.els14_all.deb
sha:45744af9945ffdcc6062b6f8e32051c8b8089fe9
-
apache2-dev_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:204b48f9d697f063ee01fba101ba8ba352663bc6
-
apache2-doc_2.4.41-4ubuntu3.23+tuxcare.els14_all.deb
sha:147d785aebbd52d9a8c0569ffb467020269c84e0
-
apache2-ssl-dev_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:bef7e19aded022fa63c5f1e4d3c1d6fd02475df3
-
apache2-suexec-custom_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:17efd7e5e27ef21698e70951f07a27b0829b3c00
-
apache2-suexec-pristine_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:5a640c1f32dd0a6a333a091a6be90a5e87d194fc
-
apache2-utils_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:81b67e2f2a999b114c08463c1619cf099d735272
-
libapache2-mod-md_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:3e501aec42e89fa74a227adba5421d4f13bc5527
-
libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.23+tuxcare.els14_amd64.deb
sha:7e04d27095373bc7d9bbbc91fe2baeb1d3a485c9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.