Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-29167: Apache on Debian can be remotely compromised
CVE-2026-29167 · published 3 days ago
Summary
The Apache web server packages for Debian (including the standard and custom builds) contain a flaw that could let an attacker run code on the server. This could lead to loss of control over the website or data. Install the latest updated Apache packages from the Debian repositories as soon as possible to close the gap.
What to do
- Update canonical apache2 to version 2.4.58-1ubuntu8.15.
- Update canonical apache2 to version 2.4.66-2ubuntu2.4.
- Update bellsoft apache2 to version 2.4.68-r0.
- Update debian apache2 to version 2.4.67-1~deb11u3.
- Update debian apache2 to version 2.4.68-1.
- Update canonical apache2 to version 2.4.52-1ubuntu4.23.
- Update debian rootio-apache2 to version 2.4.67-1~deb12u3.root.io.11.
- Update debian rootio-apache2 to version 2.4.67-1~deb13u3.root.io.3.
- Update debian apache2 to version 2.4.67-1~deb13u3.root.io.3.
- Update debian apache2 to version 2.4.68-1~deb12u1.
- Update debian apache2 to version 2.4.68-1~deb13u1.
- Update apache2 to version 2.4.67-1~deb13u3.aikido.6.
- Update rootio-apache2 to version 2.4.67-1~deb13u3.aikido.6.
- Update apache2 to version 2.4.67-1~deb12u3.aikido.13.
- Update rootio-apache2 to version 2.4.67-1~deb12u3.aikido.13.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:24.04:LTS | canonical | apache2 |
< 2.4.58-1ubuntu8.15 Fix: upgrade to 2.4.58-1ubuntu8.15
|
| Ubuntu:25.10 | canonical | apache2 | All versions |
| Ubuntu:26.04:LTS | canonical | apache2 |
< 2.4.66-2ubuntu2.4 Fix: upgrade to 2.4.66-2ubuntu2.4
|
| Debian:11 | debian | apache2 |
< 2.4.67-1~deb11u3 Fix: upgrade to 2.4.67-1~deb11u3
|
| Debian:12 | debian | apache2 |
< 2.4.68-1~deb12u1 Fix: upgrade to 2.4.68-1~deb12u1
|
| Debian:13 | debian | apache2 |
< 2.4.68-1~deb13u1 Fix: upgrade to 2.4.68-1~deb13u1
|
| Debian:14 | debian | apache2 |
< 2.4.68-1 Fix: upgrade to 2.4.68-1
|
| Alpaquita:stream | bellsoft | apache2 |
>= 2.4.56-r0, < 2.4.68-r0 Fix: upgrade to 2.4.68-r0
|
| Ubuntu:Pro:14.04:LTS | canonical | apache2 | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | apache2 | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | apache2 | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | apache2 | All versions |
| Ubuntu:22.04:LTS | canonical | apache2 |
< 2.4.52-1ubuntu4.23 Fix: upgrade to 2.4.52-1ubuntu4.23
|
| Root:Debian:12 | debian | rootio-apache2 |
< 2.4.67-1~deb12u3.root.io.11 Fix: upgrade to 2.4.67-1~deb12u3.root.io.11
|
| Root:Debian:13 | debian | rootio-apache2 |
< 2.4.67-1~deb13u3.root.io.3 Fix: upgrade to 2.4.67-1~deb13u3.root.io.3
|
| Root:Debian:13 | debian | apache2 |
< 2.4.67-1~deb13u3.root.io.3 Fix: upgrade to 2.4.67-1~deb13u3.root.io.3
|
| Root:Debian:13 | – | apache2 |
< 2.4.67-1~deb13u3.aikido.6 Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
|
| Root:Debian:13 | – | rootio-apache2 |
< 2.4.67-1~deb13u3.aikido.6 Fix: upgrade to 2.4.67-1~deb13u3.aikido.6
|
| Root:Debian:12 | – | apache2 |
< 2.4.67-1~deb12u3.aikido.13 Fix: upgrade to 2.4.67-1~deb12u3.aikido.13
|
| Root:Debian:12 | – | rootio-apache2 |
< 2.4.67-1~deb12u3.aikido.13 Fix: upgrade to 2.4.67-1~deb12u3.aikido.13
|
Original advisory text
CVE-2026-29167 in apache2 - Patched by Root
Root has patched CVE-2026-29167 in the apache2 package for Root:Debian:12. Multiple fixed versions available.
References
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://security-tracker.debian.org/tracker/CVE-2026-29167 Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/08/4
- http://www.openwall.com/lists/oss-security/2026/06/09/1
- https://docs.bell-sw.com/security/cves/CVE-2026-29167 Vendor Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29167 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-29167 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8516-1 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-29167 Third Party Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-416Use After Free
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen8 Jun 2026
Sources
CVE-2026-29167 · NVD
DEBIAN-CVE-2026-29167 · OSV
BELL-CVE-2026-29167 · OSV
UBUNTU-CVE-2026-29167 · OSV
Track software like this
Free during beta