安全更新:Apache httpd 2.4.69 RPM 和 DEB 软件包已发布,支持 HTTP/2、HTTP/3、Brotli、TLS 1.3、OpenSSL 4.0.3 和 ALPN,适用于 EL7/EL8/EL9/EL10, Ubuntu 22.04/24.04

Apache httpd 2.4.69 已新增到 CodeIT 仓库,编译时启用了 HTTP/2(mod_http2)、Brotli、TLS 1.3 和 ALPN,并基于 OpenSSL 4.0.3。这些软件包适用于 RHEL、CentOS、AlmaLinux、Rocky Linux 和 Oracle Linux 7、8、9 和 10,以及 Ubuntu 22.04 和 24.04。

本次更新修复了安全漏洞,建议尽快升级。

从 2.4.69 起,mod_ssl 改为基于 OpenSSL 3.0 API 而非 1.1.1 编译(OPENSSL_API_COMPAT 从 1.1.1 提升到 3.0.0),因为 OpenSSL 4.0 移除了在 3.0 之前已被弃用的功能。SRP(TLS-SRP,RFC 5054)也随之移除:SSLSRPVerifierFile 和 SSLSRPUnknownUserSeed 指令已不存在,请在升级前从配置中删除,否则 httpd 将无法启动;SSL_SRP_USER 和 SSL_SRP_USERINFO 变量也不再设置。这些软件包中的 ENGINE API 此前已被禁用。

RPM 软件包中的 mod_http2 现在直接从 httpd 源码树编译,与 DEB 软件包及 Ubuntu 自带的 apache2 一致,不再来自独立的 mod_h2 项目。软件包名称仍为 mod_http2,版本号改为随 httpd,因此 dnf 或 yum 会自动从 mod_http2 2.0.42 升级到它:无需事先卸载,修改过的 10-h2.conf 也会保留。

此版本 httpd 可通过 mod_http3 使用 HTTP/3,这是一个单独打包的实验性模块:

  • RPM,EL8 及更高版本:dnf install mod_http3
  • RPM,EL7:yum install mod_http3
  • DEB:apt install libapache2-mod-http3

模块安装后即被加载,HTTP/3 需按虚拟主机启用。编辑软件包安装的示例 vhost(ServerName 和证书):在 EL 上是 /etc/httpd/vhosts.d/http3-vhost.conf,httpd.conf 默认不包含它,请添加 IncludeOptional vhosts.d/*.conf;在 Ubuntu 上运行 a2ensite http3-vhost。然后重新加载 httpd,并在防火墙中开放 443/udp,因为 QUIC 基于 UDP。

主要变更:

  • 修复了文档中的 tar 图标,使其背景为透明。PR 70238。
  • mod_ssl:修复了 OpenSSL 兼容性宏,用于 X509_get0_notBefore、X509_get0_notAfter 和 X509_get0_serialNumber,并适配 OpenSSL < 1.1。PR 70205。
  • mod_cgid、mod_ssl、mod_md:多项加固修复。
  • mod_md:MDServerStatus 默认处于禁用状态。
  • mod_auth_digest:修复了与基于表达式的 AuthName 的兼容性。PR 59039。
  • mod_auth_digest.c:移除了对 RFC 2069 的支持;重写共享内存处理以及 client nonce 处理;”authdigest-opaque” 互斥锁不再需要。
  • mod_lbmethod_heartbeat:使用带范围校验的安全整数解析,替换 atoi()。
  • core:拒绝中间响应的 reason phrase 中的控制字符。仅接受空格作为状态码分隔符。
  • mod_substitute:修复了 SubstituteMaxLineLength,使其拒绝超过 K/M/G 后缀可表示范围的过大数值。
  • mod_substitute:修复在加载 Substitute 指令时若缺少结束定界符会导致崩溃或异常行为的问题。
  • mod_dir:修复了 fixup_dir 在请求未映射到任何类型时发生的崩溃。PR68527。
  • mod_http2:当客户端在仍在处理其已打开 streams 的情况下发送 graceful GOAWAY(error code 0)时,不会丢弃正在进行中的响应。现在会将打开的 streams 进行排空处理,而不是立刻拆除;这比 event 更常被异步 MPM 触发。此修复解决了静默丢弃的响应问题,并符合 RFC 9113。
  • mod_md:添加对 OpenSSL 4 的兼容性。
  • pytest_suite:将旧的 PERL 测试框架移植到 Python 与 pytest。现在已随源代码一起提供,并位于 ./test 下。

修复的漏洞:

  • SECURITY: CVE-2026-93546: mod_dav_fs namespace overflow Integer overflow in mod_dav_fs in Apache HTTP Server through 2.4.68 allows an authenticated WebDAV client with write access to crash worker processes and persistently corrupt a directory’s property database via PROPPATCH requests declaring many XML namespaces.
  • SECURITY:CVE-2026-79768:mod_userdir:修复了信息泄露问题。修复了路径等价性漏洞 ‘/./’(单点目录)——当 Apache HTTP Server 的 mod_userdir 模块配置为绝对且不含通配符的 UserDir 指令(第二种形式)时,该问题会产生影响。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-73637:mod_auth_digest:修复了 DoS 攻击——修复了 mod_auth_digest 中的 use after free(Apache Software Foundation Apache HTTP Server 2.4.69 之前的所有平台)。该问题原本允许未认证的远程客户端在启用 AuthDigestNcCheck 或将 AuthDigestNonceLifetime 设置为 0 时,通过并发的 Digest 认证请求破坏认证状态。
  • SECURITY: CVE-2026-73636: mod_auth_digest one-time-nonce replay attack Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client’s shared memory entry when AuthDigestNonceLifetime is set to 0. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY:CVE-2026-63718:mod_proxy_uwsgi:修复了 Transfer-Encoding 响应走私问题。修复了通过 mod_proxy_uwsgi 以及带 Transfer-Encoding 的构造 uwsgi 响应所导致的响应走私漏洞,该漏洞源于对 HTTP 请求的解释不一致(”HTTP Request/Response Smuggling”)。该问题影响 Apache HTTP Server:从 2.4.30 到 2.4.68。
  • SECURITY: CVE-2026-63686: mod_xml2enc crash on charset conversion failure A NULL pointer dereference in mod_xml2enc in Apache Software Foundation Apache HTTP Server before 2.4.69 on all platforms allows an untrusted backend server to cause a denial of service via a proxied response with a charset whose conversion partially succeeds then fails. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63292: mod_vhost_alias stack overflow Stack-based buffer overflow in mod_vhost_alias in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows a remote client to cause a denial of service or potentially execute arbitrary code via an HTTP request with a Host header exceeding 8192 bytes when VirtualDocumentRoot uses a hostname format specifier and LimitRequestFieldSize is raised above the default. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY: CVE-2026-63045: mod_proxy_ftp PASV address handling Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
  • SECURITY:CVE-2026-59797:mod_ssl:SSLRequire 不再允许 .htaccess 的 ap_expr 使用 file-function。修复了 Apache HTTP Server 的 mod_ssl 中通过 SSLRequire 和与文件相关的表达式导致的权限管理不当问题。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-59685:修复了 ap_directory_walk() 中越界写入;在 CASE_BLIND_FILESYSTEM 下执行 Canonical-Name Rewrite。修复了 Apache HTTP Server(Windows)在处理可能扩展后会增长的 8.3 名称路径时的越界写入漏洞。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-58415:mod_dav_fs:修复了属性数据库的读取权限问题。修复了 Apache Software Foundation Apache HTTP Server 2.4.69 之前所有平台中 mod_dav_fs 内部状态文件可被外部访问的问题:现在远程客户端无法通过对 .DAV 状态目录发起 GET 请求来读取它无权授权的资源的 WebDAV dead properties。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-57941:mod_http2:修复了 use-after-free / 通过 shared session->bbtmp re-entrancy 的任意写入。修复了 Apache HTTP Server 的 mod_http2 中通过共享 session->bbtmp re-entrancy 引发的 use-after-free 漏洞。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-56449:mod_proxy_html:修复了 dump_content 中的崩溃。修复了 Apache HTTP Server 的 mod_proxy_html 在使用构造的 HTTP 响应体时的越界写入漏洞。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-56154:mod_rewrite:修复了通过 %{LA-U:HTTP…} 导致的 use-after-free。修复了在使用 lookahead(%{LA-U:HTTP…})时 Apache HTTP Server 的 mod_rewrite 中的 use-after-free 漏洞。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-56153:mod_charset_lite:修复了 finish_partial_char 中的堆溢出。修复了 Apache HTTP Server 的 mod_charset_lite 中的越界写入漏洞。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-48005:mod_auth_digest:修复了重新认证攻击。修复了 Apache Software Foundation Apache HTTP Server 2.4.69 之前所有平台中 mod_auth_digest 缺失认证检查的问题:当使用 AuthDigestNcCheck 启用 Digest 认证时,未认证的远程客户端不再能够通过伪造的 Authorization 头触发拒绝服务(强制重新认证)。
  • SECURITY:CVE-2026-47360:mod_session:内部重定向期间不会再移除会话 Cookie。修复了 Apache HTTP Server 的 mod_session_cookie 模块中向未授权主体泄露敏感信息的漏洞。
  • SECURITY:CVE-2026-46729:mod_heartmonitor:修复了拒绝服务。修复了 Apache HTTP Server 的 mod_heartmonitor 在通过单播监听器时触发的 NULL 指针解引用漏洞。该问题影响 Apache HTTP Server:从 2.4.0 到 2.4.68。
  • SECURITY:CVE-2026-42528:mod_dav:修复了共享锁溢出。修复了 Apache httpd 2.4.67 及更早版本中的 mod_dav 内存计算错误:攻击者在拥有创建 WebDAV 锁的权限时,不再能够导致服务器子进程崩溃。建议升级到 2.4.69 版本,该版本修复了此问题
  • SECURITY:CVE-2026-42356:修复了针对 CGI 目录中某些非 CGI 文件的内部重定向导致的受限 RCE。修复了 Apache HTTP Server 中“错误处理器”漏洞:它会导致某些来自 CGI 程序的内部重定向目标也被当作 CGI,从而执行。该目标必须已位于启用 CGI 的目录中,并且不能具有 mod_mime 能理解的其他扩展名。该问题影响 Apache HTTP Server:从 2.4.60 到 2.4.68。