Advisories ยป MGASA-2026-0364

Updated apr-util packages fix security vulnerabilities

Publication date: 02 Sep 2026
Modification date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502

Description

Apache Portable Runtime Utility: apr_password_validate() vulnerable to
timing attack. (CVE-2025-49506)
Apache Portable Runtime Utility: apr-util XML stack recursion crash.
(CVE-2026-32327)
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle.
(CVE-2026-34191)
Apache Portable Runtime Utility: Heap buffer overflow in APR redis
client. (CVE-2026-34501)
Apache Portable Runtime Utility: Heap buffer overflow in APR memcached
client. (CVE-2026-34502)
                

References

SRPMS

10/core

9/core