ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 15 sources: “Ubuntu security roundup (2026-09-10 to 2026-09-16): ten notices fix 15 named CVEs across .NET, Netty, glibc, PHP, Python, Apache HTTP Server, GNU Guix, Perl, libheif and…” — merged summary and timeline →

USN-8571-2: Apache HTTP Server regression

lowAdvisoryimportance 28CVE-2026-33007
AI summary · glm-5.3-flash

Ubuntu issues USN-8571-2 fixing an Apache HTTP Server regression that prevented startup when HTTP/2 proxying was enabled.

Ubuntu released USN-8571-2 to fix a regression introduced by USN-8571-1 in Apache HTTP Server. The earlier fix was incomplete due to a missing library symbol, causing Apache to fail to start when HTTP/2 proxying was enabled. The original advisory addressed CVE-2026-33007, a memory-handling flaw in mod_authn_socache allowing remote denial of service, and an HTTP response splitting vulnerability affecting multiple modules, credited to Pavel Kohout, Arkadi Vainbrand, Haruki Oyama, Merih Mengisteab, and Dawit Jeong.

  • USN-8571-2 fixes Apache startup failure with HTTP/2 proxying enabled
  • Regression stemmed from a missing library symbol in USN-8571-1
  • Underlying issues include CVE-2026-33007 DoS in mod_authn_socache
  • HTTP response splitting flaw was fixed in multiple Apache modules

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-33007
A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a

A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated remote user to crash a child process in a caching forward proxy configuration. Users are recommended to upgrade to version 2.4.67, which fixes this issue.

NVD description · AI analysis pending
5.3<1%
  • apache http server
Full article

USN-8571-1 fixed vulnerabilities in Apache HTTP Server. That fix was incomplete due to a missing library symbol, resulting in a regression that could cause Apache HTTP Server to fail to start when HTTP/2 proxying was enabled. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Pavel Kohout and Arkadi Vainbrand discovered that Apache HTTP Server incorrectly handled certain memory operations in mod_authn_socache. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2026-33007) Haruki Oyama, Merih Mengisteab, and Dawit Jeong discovered that Apache HTTP Server had an HTTP response splitting vulnerability in multiple modules…

This source does not provide full text. Read it at ubuntu.com.