Updated apr-util packages fix security vulnerabilities
Publication date: 02 Sep 2026Modification date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2025-49506 , CVE-2026-32327 , CVE-2026-34191 , CVE-2026-34501 , CVE-2026-34502
Description
Apache Portable Runtime Utility: apr_password_validate() vulnerable to
timing attack. (CVE-2025-49506)
Apache Portable Runtime Utility: apr-util XML stack recursion crash.
(CVE-2026-32327)
Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle.
(CVE-2026-34191)
Apache Portable Runtime Utility: Heap buffer overflow in APR redis
client. (CVE-2026-34501)
Apache Portable Runtime Utility: Heap buffer overflow in APR memcached
client. (CVE-2026-34502)
References
- https://bugs.mageia.org/show_bug.cgi?id=36181
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKNIDBBNHOGIQ7XPC4JGLXADWZC3JEUN/
- https://lists.debian.org/debian-security-announce/2026/msg00348.html
- https://www.cve.org/CVERecord?id=CVE-2025-49506
- https://www.cve.org/CVERecord?id=CVE-2026-32327
- https://www.cve.org/CVERecord?id=CVE-2026-34191
- https://www.cve.org/CVERecord?id=CVE-2026-34501
- https://www.cve.org/CVERecord?id=CVE-2026-34502
SRPMS
10/core
- apr-util-1.6.3-3.1.mga10
9/core
- apr-util-1.6.3-1.1.mga9