{"schema_version":"1.7.5","id":"SUSE-SU-2026:22199-1","published":"2026-06-20T06:57:50Z","modified":"2026-06-24T09:00:08.114414454Z","related":["CVE-2026-23918","CVE-2026-24072","CVE-2026-28780","CVE-2026-29168","CVE-2026-29169","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059"],"upstream":["CVE-2026-23918","CVE-2026-24072","CVE-2026-28780","CVE-2026-29168","CVE-2026-29169","CVE-2026-33006","CVE-2026-33007","CVE-2026-33523","CVE-2026-33857","CVE-2026-34032","CVE-2026-34059"],"summary":"Security update for apache2","details":"This update for apache2 fixes the following issues\n\n- CVE-2026-23918: http2: double free and possible RCE on early reset (bsc#1263957).\n- CVE-2026-24072: mod_rewrite elevation of privileges via ap_expr (bsc#1263935).\n- CVE-2026-28780: heap buffer overflow in `mod_proxy_ajp` via `ajp_msg_check_header()` (bsc#1264163).\n- CVE-2026-29168: allocation of resources without limits in `mod_md` via OCSP response (bsc#1264150).\n- CVE-2026-29169: NULL pointer dereference in `mod_dav_lock` allows server crash via malicious requests (bsc#1263956).\n- CVE-2026-33006: `mod_auth_digest` timing attack allows bypass of Digest authentication (bsc#1263955).\n- CVE-2026-33007: NULL pointer dereference in `mod_authn_socache` allows unauthenticated remote user to crash a child\n  processes (bsc#1263954).\n- CVE-2026-33523: HTTP response splitting forwarding malicious status line (bsc#1263953).\n- CVE-2026-33857: off-by-one OOB reads in AJP getter functions (bsc#1263952).\n- CVE-2026-34032: heap buffer overread in `mod_proxy_ajp` due to missing null-termination check (bsc#1263951).\n- CVE-2026-34059: heap buffer overread and memory disclosure via `ajp_parse_data()` (bsc#1263950).\n","affected":[{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-devel","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-event","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-manual","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-prefork","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-utils","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-worker","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-devel","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-event","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-manual","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2-manual&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-prefork","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-utils","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}},{"package":{"name":"apache2-worker","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.66-160000.2.1"}]}],"ecosystem_specific":{"binaries":[{"apache2":"2.4.66-160000.2.1","apache2-devel":"2.4.66-160000.2.1","apache2-event":"2.4.66-160000.2.1","apache2-manual":"2.4.66-160000.2.1","apache2-prefork":"2.4.66-160000.2.1","apache2-utils":"2.4.66-160000.2.1","apache2-worker":"2.4.66-160000.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:22199-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202622199-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263935"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263951"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263952"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263953"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263956"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263957"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264163"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-23918"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-24072"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28780"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29168"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-29169"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33006"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33007"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33857"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34032"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-34059"}]}