Views
11

Your rating
Rate update installation process

Log in to rate this update.
Login

Risk factor
No ratings yet. Be the first to rate this update.

Smooth installs 0%
Minor issues 0%
Major issues 0%

AI enhanced content

Update Summary

USN-8719-1 updates APR-util for Ubuntu 24.04 LTS (noble) to address four security issues, including CVE-2025-49506, CVE-2026-32327, CVE-2026-34501, and CVE-2026-34502. The update fixes information disclosure, denial of service, and possible remote code execution risks.

Update Details

Security

  • Fixes non-constant-time password hash comparisons that could leak sensitive information (CVE-2025-49506).
  • Fixes recursive XML element quoting handling that could let an attacker crash applications, causing a denial of service (CVE-2026-32327).
  • Fixes Redis client network data handling that could cause a heap-based buffer overflow and possibly allow crash or arbitrary code execution (CVE-2026-34501).
  • Fixes memcached client network data handling that could cause a heap-based buffer overflow and possibly allow crash or arbitrary code execution (CVE-2026-34502).

Hints

  • A standard system update installs the required fix.
  • For Ubuntu 24.04 LTS (noble), update libaprutil1t64 to 1.6.3-1.1ubuntu7.1.

Product Information

Vendor: Canonical

Product: Ubuntu Server

Product type: Software

Application category: Utilities

Platform: Linux

Variant: 24.04 LTS (Noble Numbat)

Version: 1.6.3-1.1ubuntu7.1

Vendor release date: Sep 3, 2026

Original release notes: View on vendor site

Published on updatealert.io: Sep 6, 2026

Description: Server operating system for Linux infrastructure and workloads.