Security update: apr-util 1.6.5 RPM and DEB packages released

apr-util 1.6.5 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • Fix oracle DBD compilation errors introduced in 1.6.4. PR 70170.
  • apr_brigade: Don’t split the final LF in apr_brigade_split_line() to avoid producing an empty bucket. PR 64273
  • apr_brigade: Metadata buckets are now ignored in apr_brigade_split_line, apr_brigade_flatten and apr_brigade_to_iovec, fixing possible undefined behaviour. PR 68278
  • apr_crypto_openssl: Compatibility with OpenSSL 3.
  • apr_crypto_openssl: use OPENSSL_init_crypto() to initialise OpenSSL on versions 1.1+.
  • apr_memcache: Fix name lookup to allow IPv6 as well as IPv4.
  • configure: Fix Berkeley DB detection with compilers enforcing strict C99 compliance. PR 66396.

Fixed vulnerabilities:

  • SECURITY: CVE-2026-34502: Heap buffer overflow in APR memcached client Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: from 1.3.0 through 1.6.3.
  • SECURITY: CVE-2026-34501: Apache Portable Runtime Utility: Heap buffer overflow in APR redis client Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
  • SECURITY: CVE-2026-34191: Apache Portable Runtime Utility: SQL Injection in apr_dbd_oracle Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in Apache Portable Runtime Utility via apr_dbd_oracle provider. This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade to version 1.6.4, which fixes the issue.
  • SECURITY: CVE-2026-32327: Apache Portable Runtime Utility: apr-util XML stack recursion crash A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources and uses the apr_xml_quote_elem() function. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
  • SECURITY: CVE-2025-49506: apr_password_validate() vulnerable to timing attack APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as  Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.