Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (16)
📋 Description
CVE-2026-42356 — httpd: httpd: arbitrary code execution via incorrect handler assignment during internal CGI redirects CVE-2026-42528 — httpd: httpd: Denial of Service via mod_dav shared lock memory calculation error CVE-2026-46729 — httpd: httpd: mod_heartmonitor: Denial of Service via NULL pointer dereference CVE-2026-47360 — httpd: httpd: Information disclosure via session cookie leakage during internal redirects CVE-2026-48005 — httpd: httpd: Denial of service via forged Authorization headers in mod_auth_digest CVE-2026-56153 — httpd: httpd: Denial of Service via heap-based buffer overflow in mod_charset_lite CVE-2026-56449 — httpd: httpd: Denial of Service via crafted HTTP response bodies in mod_proxy_html CVE-2026-58415 — httpd: httpd: Information disclosure via direct request to the WebDAV state directory CVE-2026-63045 — httpd: httpd: unauthorized connection to arbitrary hosts via crafted FTP PASV response CVE-2026-63292 — httpd: httpd: Arbitrary code execution via oversized Host header in mod_vhost_alias CVE-2026-63686 — httpd: httpd: Denial of Service via charset conversion failure in mod_xml2enc CVE-2026-63718 — httpd: httpd: HTTP response smuggling via crafted Transfer-Encoding response in mod_proxy_uwsgi CVE-2026-73636 — httpd: httpd: Authentication bypass via credential replay in mod_auth_digest CVE-2026-73637 — httpd: httpd: Authentication state corruption via concurrent Digest authentication requests CVE-2026-79768 — httpd: httpd: Information disclosure in mod_userdir via single-dot path equivalence CVE-2026-93546 — httpd: httpd: Denial of Service via integer overflow in mod_dav_fs
🎯 Affected products24
- Red Hat Hardened Images
- httpd-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- httpd-0:2.4.69-1.hum1@src as a component of Red Hat Hardened Images
- httpd-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- httpd-core-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- httpd-core-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- httpd-devel-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- httpd-devel-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- httpd-filesystem-0:2.4.69-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- httpd-filesystem-0:2.4.69-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- httpd-manual-0:2.4.69-1.hum1@noarch@public-hummingbird-aarch64-rpms as a component of Red Hat Hardened Images
- httpd-manual-0:2.4.69-1.hum1@noarch@public-hummingbird-x86_64-rpms as a component of Red Hat Hardened Images
- httpd-tools-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- httpd-tools-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- mod_ldap-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- mod_ldap-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- mod_lua-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- mod_lua-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- mod_proxy_html-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- mod_proxy_html-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- mod_session-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- mod_session-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
- mod_ssl-0:2.4.69-1.hum1@aarch64 as a component of Red Hat Hardened Images
- mod_ssl-0:2.4.69-1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: If CGI functionality is not required, disable CGI execution by commenting out `mod_cgi` or `mod_cgid` in the Apache configuration (for example, in `/etc/httpd/conf.modules.d/01-cgi.conf`), or by removing `ExecCGI` from `Options` directives in `/etc/httpd/conf/httpd.conf`. Apply the changes to the running service: systemctl reload httpd Caveats: Disabling CGI modules or execution options will prevent any existing CGI applications from functioning. Warning: Reloading or restarting the httpd service may temporarily disrupt active connections. Workaround: If WebDAV functionality is not required, disable the mod_dav module by commenting out the `LoadModule dav_module` line in `/etc/httpd/conf.modules.d/00-dav.conf` or setting `Dav Off` within the relevant configuration contexts. If WebDAV is required, restrict lock capabilities to authenticated and trusted clients by limiting the LOCK method within the configuration (for example, using `<Limit LOCK>` blocks with strict `Require` directives). Apply configuration changes by reloading the service: ``` systemctl reload httpd ``` Warning: Disabling mod_dav or restricting lock operations will prevent WebDAV clients from acquiring shared or exclusive resource locks. Reloading the httpd service may briefly affect active HTTP connections. Workaround: Disable the mod_heartmonitor module or restrict network access to the monitoring port: 1. Disable the module: Comment out the LoadModule directive for mod_heartmonitor in the Apache configuration (typically located in `/etc/httpd/conf.modules.d/00-base.conf` or a custom configuration file): # LoadModule heartmonitor_module modules/mod_heartmonitor.so Then reload the web server configuration: systemctl reload httpd 2. Restrict network reachability: If mod_heartmonitor is required, configure firewall rules using firewalld to permit traffic to the HeartbeatListen unicast port only from authorized backend nodes: firewall-cmd --permanent --zone=trusted --add-source=<TRUSTED_IP_RANGE> firewall-cmd --reload Caveat: Disabling mod_heartmonitor prevents mod_lbmethod_heartbeat from receiving backend node status, which disables heartbeat-based dynamic load balancing. Warning: Modifying Apache configuration files requires reloading or restarting httpd, which may briefly interrupt active network connections. Workaround: If cookie-based session management is not required, disable the `mod_session_cookie` module. 1. Comment out the module load directive in `/etc/httpd/conf.modules.d/01-session.conf` (or the relevant configuration file): ``` # LoadModule session_cookie_module modules/mod_session_cookie.so ``` 2. Reload the `httpd` service to apply the configuration: ``` systemctl reload httpd ``` Warning: Reloading or restarting the `httpd` service may briefly interrupt active network connections. Additionally, disabling this module will cause any web server configurations or web applications relying on `mod_session_cookie` to fail. Workaround: To mitigate this issue, disable nonce-count verification by setting `AuthDigestNcCheck Off` within the relevant configuration context in `/etc/httpd/conf/httpd.conf` or `/etc/httpd/conf.d/`: AuthDigestNcCheck Off Alternatively, if Digest authentication is not required, disable `mod_auth_digest` by commenting out the corresponding `LoadModule auth_digest_module` line in `/etc/httpd/conf.modules.d/00-base.conf`. After modifying the configuration, reload the service: systemctl reload httpd Caveats: Disabling `AuthDigestNcCheck` removes server-side nonce-count checking, reducing replay protection for Digest authentication. Warning: Reloading the httpd service can momentarily disrupt in-flight connections. Workaround: Disable the mod_charset_lite module if character set translation is not required. 1. Locate the configuration file loading the module, typically within `/etc/httpd/conf.modules.d/` (such as `00-base.conf` or a dedicated module configuration file). 2. Comment out or remove the `LoadModule charset_lite_module` line: ``` # LoadModule charset_lite_module modules/mod_charset_lite.so ``` 3. Reload the httpd service to apply the configuration change: ``` systemctl reload httpd ``` Caveats: Applications that depend on mod_charset_lite for on-the-fly character set conversion will fail to translate character sets once the module is disabled. Warning: Reloading or restarting the httpd service will momentarily disrupt active network connections or in-flight requests. Workaround: Disable the `mod_proxy_html` module if HTML link rewriting is not required: 1. Comment out the module loader directive in `/etc/httpd/conf.modules.d/00-proxyhtml.conf`: ``` # sed -i 's/^\s*LoadModule proxy_html_module/#&/' /etc/httpd/conf.modules.d/00-proxyhtml.conf ``` Alternatively, set `ProxyHTMLEnable Off` in the affected server or virtual host configuration. 2. Reload the Apache HTTP Server: ``` # systemctl reload httpd ``` Caveats: Disabling `mod_proxy_html` or turning off `ProxyHTMLEnable` halts automated rewriting of URLs in proxied HTML responses, which may break web applications that depend on backend path translation. Warning: Reloading or restarting the `httpd` service may temporarily interrupt active network connections. Workaround: To mitigate this flaw, block direct HTTP requests to the internal WebDAV state directory, or disable the mod_dav_fs module if WebDAV functionality is not required. 1. Block access to the .DAV directory: Create or edit a configuration snippet, such as `/etc/httpd/conf.d/block-dav-state.conf`, with the following directive: <LocationMatch "(^|/)\.DAV"> Require all denied </LocationMatch> 2. Alternatively, disable the module if WebDAV is not used: Comment out the following line in `/etc/httpd/conf.modules.d/00-dav.conf`: # LoadModule dav_fs_module modules/mod_dav_fs.so 3. Apply changes: Verify the configuration syntax: # apachectl configtest Reload the service: # systemctl reload httpd Warning: Reloading or restarting httpd will impact active network connections. Ensure configuration syntax is validated before reloading to avoid service interruption. Disabling mod_dav_fs will stop all WebDAV filesystem storage operations. Workaround: Disable the mod_proxy_ftp module or ensure forward proxying is disabled in the Apache HTTP Server configuration. 1. Comment out the mod_proxy_ftp module load line in `/etc/httpd/conf.modules.d/00-proxy.conf`: ``` # LoadModule proxy_ftp_module modules/mod_proxy_ftp.so ``` 2. Ensure forward proxying is turned off in `/etc/httpd/conf/httpd.conf`: ``` ProxyRequests Off ``` 3. Reload the httpd service to apply changes: ``` systemctl reload httpd ``` Caveat: Disabling mod_proxy_ftp terminates the ability of httpd to proxy FTP requests. Warning: Reloading or restarting the httpd service will briefly affect active connections while configuration changes are reloaded. Workaround: To mitigate this vulnerability without code modifications, ensure that `LimitRequestFieldSize` remains at or below its default limit of 8190 bytes, or disable the `mod_vhost_alias` module if dynamic virtual hosting is not required. 1. Ensure `LimitRequestFieldSize` is not configured above 8190 in `/etc/httpd/conf/httpd.conf` or `/etc/httpd/conf.d/`: ``` LimitRequestFieldSize 8190 ``` 2. Alternatively, if `mod_vhost_alias` is not needed, disable it by commenting out its loading directive in `/etc/httpd/conf.modules.d/00-base.conf`: ``` # LoadModule vhost_alias_module modules/mod_vhost_alias.so ``` 3. Validate the configuration syntax and reload the service: ``` apachectl configtest systemctl reload httpd ``` Caveats: Restricting `LimitRequestFieldSize` may reject legitimate requests that carry exceptionally large HTTP headers, returning a 400 Bad Request response. Disabling `mod_vhost_alias` prevents the use of dynamic virtual host directives…
🔗 References (20)
- selfhttps://access.redhat.com/errata/RHSA-2026:74858
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-47360
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-42356
- externalhttps://access.redhat.com/security/cve/CVE-2026-48005
- externalhttps://access.redhat.com/security/cve/CVE-2026-73636
- externalhttps://access.redhat.com/security/cve/CVE-2026-58415
- externalhttps://access.redhat.com/security/cve/CVE-2026-56153
- externalhttps://access.redhat.com/security/cve/CVE-2026-46729
- externalhttps://access.redhat.com/security/cve/CVE-2026-63045
- externalhttps://access.redhat.com/security/cve/CVE-2026-63292
- externalhttps://access.redhat.com/security/cve/CVE-2026-42528
- externalhttps://access.redhat.com/security/cve/CVE-2026-63686
- externalhttps://access.redhat.com/security/cve/CVE-2026-73637
- externalhttps://access.redhat.com/security/cve/CVE-2026-93546
- externalhttps://access.redhat.com/security/cve/CVE-2026-56449
- externalhttps://access.redhat.com/security/cve/CVE-2026-79768
- externalhttps://access.redhat.com/security/cve/CVE-2026-63718
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74858.json