Release date:
2026-07-24 14:38:06 UTC
Description:
* SECURITY UPDATE: use-after-free in mod_http2 when file handles are
exhausted
- debian/patches/CVE-2026-48913.patch: in c2_setup_io() in
modules/http2/h2_mplx.c, register the beam input callbacks
(h2_beam_on_send/received/consumed) only after the H2_USE_PIPES input
pipe has been created, so a pipe-creation failure under file-handle
exhaustion no longer leaves the callbacks referencing the torn-down
secondary (c2) connection. Backported from mod_http2 commit
d600b257c4714e43a2be8f5c9e1e5105f1d8f7ec (mod_http2 v2.0.40).
- CVE-2026-48913
Updated packages:
-
apache2_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:bd37c37a531feb8c0573d88aecc2d96087c34eb6
-
apache2-bin_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:db72f41842984450acaea27119551bacef0a0a56
-
apache2-data_2.4.41-4ubuntu3.23+tuxcare.els13_all.deb
sha:338895db8dd745db387c5b9a5c56445b6a199fe2
-
apache2-dev_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:2d3532704ff07b6398d3446370b3a6deeb5f02e6
-
apache2-doc_2.4.41-4ubuntu3.23+tuxcare.els13_all.deb
sha:49201c5fde9a52400b3cc3efeb2480b236a175aa
-
apache2-ssl-dev_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:5157799f94c9e935978069670c0581e28d07e6a5
-
apache2-suexec-custom_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:97d0017bcc1105a7fbfc0f192b573c0e91b289f0
-
apache2-suexec-pristine_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:adbe0137e1db1c608e51eb60fc9b5b35f2ab5c49
-
apache2-utils_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:f2d61d1955247e3941c7a53227049ae7b1aea24d
-
libapache2-mod-md_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:2535393a8c57cd3c1d222611236f748de56ffbb3
-
libapache2-mod-proxy-uwsgi_2.4.41-4ubuntu3.23+tuxcare.els13_amd64.deb
sha:2615369a79ff9abd66c02eadce685c912a7937c7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.