#1143837 apr-util: CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34501 CVE-2026-34502 #1143837
- Package:
- src:apr-util
- Source:
- src:apr-util
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-18 21:49:03 UTC
- Severity:
- normal
- Tags:
Hi,
The following vulnerabilities were published for apr-util.
CVE-2025-49506[0]:
| APR-util versions 1.6.3 (and earlier) function
| apr_password_validate() was not constant-time with regards to hashes
| or passwords comparisons, potentially leaking their content via a
| side channel timing attack particularly on platforms without crypt()
| such as Windows, BeOS, NetWare, or Android. Users are recommended
| to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-32327[1]:
| A bug in APR-util version 1.6.3 (and earlier) allows a stack
| recursion attack against any library consumer which parses XML from
| untrusted sources and uses the apr_xml_quote_elem() function. Users
| are recommended to upgrade to version 1.6.4, which fixes this issue.
CVE-2026-34191[2]:
| Improper Neutralization of Special Elements used in an SQL Command
| ('SQL Injection') vulnerability in Apache Portable Runtime Utility
| via apr_dbd_oracle provider. This issue affects Apache Portable
| Runtime Utility: from 1.6.0 through 1.6.3
CVE-2026-34501[3]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility redis client. This issue affects Apache Portable Runtime
| Utility: from 1.6.0 through 1.6.3. Users are recommended to upgrade
| to version 1.6.4, which fixes the issue.
CVE-2026-34502[4]:
| Heap-based Buffer Overflow vulnerability in Apache Portable Runtime
| Utility memcached client This issue affects Apache Portable Runtime
| Utility: from 1.3.0 through 1.6.3.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-49506
https://www.cve.org/CVERecord?id=CVE-2025-49506
[1] https://security-tracker.debian.org/tracker/CVE-2026-32327
https://www.cve.org/CVERecord?id=CVE-2026-32327
[2] https://security-tracker.debian.org/tracker/CVE-2026-34191
https://www.cve.org/CVERecord?id=CVE-2026-34191
[3] https://security-tracker.debian.org/tracker/CVE-2026-34501
https://www.cve.org/CVERecord?id=CVE-2026-34501
[4] https://security-tracker.debian.org/tracker/CVE-2026-34502
https://www.cve.org/CVERecord?id=CVE-2026-34502
Regards,
Salvatore
We believe that the bug you reported is fixed in the latest version of
apr-util, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143837@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Stefan Fritsch <sf@debian.org> (supplier of updated apr-util package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 07 Aug 2026 16:47:11 +0200
Source: apr-util
Architecture: source
Version: 1.6.4-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org>
Changed-By: Stefan Fritsch <sf@debian.org>
Closes: 1137309 1143837
Changes:
apr-util (1.6.4-1) unstable; urgency=medium
.
* New upstream release. Closes: #1143837
- CVE-2025-49506: apr_password_validate() vulnerable to timing attack
- CVE-2026-32327: XML stack recursion crash
- CVE-2026-34191: SQL Injection in apr_dbd_oracle
- CVE-2026-34501: Heap buffer overflow in APR redis client
- CVE-2026-34502: Heap buffer overflow in APR memcached client
* Switch Build-Depends to libmariadb-dev-compat. Closes: #1137309
Checksums-Sha1:
05cf8eed3049bbc4064b19469f89b500fde25a33 2785 apr-util_1.6.4-1.dsc
913c44f9fdfb4ce7c270a71a52402d33adcd99b6 441511 apr-util_1.6.4.orig.tar.bz2
0f6ce32a62a43287583020980f4ee92863a6ddd9 898 apr-util_1.6.4.orig.tar.bz2.asc
628aff0f2656a2445f534e90e3bc4c83efd96be8 341248 apr-util_1.6.4-1.debian.tar.xz
7cc98e36a29cf49fc43ebf63d87cf883bdf590fc 8868 apr-util_1.6.4-1_source.buildinfo
Checksums-Sha256:
1949bd1da9929e3fa89e7dc3228a9ff229ef4e051859e08c4276088a27a5ebe0 2785 apr-util_1.6.4-1.dsc
3e2ae08f40efa0c3701e54a954cefa08242de22a69f91a8ae44fc1e624ba309b 441511 apr-util_1.6.4.orig.tar.bz2
17eb58050f65c3889195f3077e36521a9af3e36b100efef690f50916c3116bf8 898 apr-util_1.6.4.orig.tar.bz2.asc
c7b5d7f28207a71d2da66097c0cec9f5c16d8df5a4e2749668de9bd9387b2c52 341248 apr-util_1.6.4-1.debian.tar.xz
ae3cad3210b39b1d6decc8ba3dcbeb87cebdfeb8b007aa4302b705331f615a78 8868 apr-util_1.6.4-1_source.buildinfo
Files:
6ed9c453a7b2fac39ceaf4b52f75e18c 2785 libs optional apr-util_1.6.4-1.dsc
8c933056e21005f69225ec6ffd0a16d3 441511 libs optional apr-util_1.6.4.orig.tar.bz2
97e710b9cfafb504e05535cd333ac2b6 898 libs optional apr-util_1.6.4.orig.tar.bz2.asc
77fe06bcd2cc04a3e31f6a2865a9b304 341248 libs optional apr-util_1.6.4-1.debian.tar.xz
f0636d01caa704fced3bce64f3549a48 8868 libs optional apr-util_1.6.4-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAmp18PAACgkQxodfNUHO
/eBhtw/+MlsN3Ims0oKb/8dh+6wpC2OVgsHVfZ+3Fh/HIyhBWPtXKjTKVs4qsgpH
/oaM2YoFmNg9u18ZuK3tPbso9ZVyBLod/hjhdBf2bY9v1rSa6FmF1rugKMuGFPid
JqBgHkUqV2BbgTsuUNsgzzDq1jA0n+WMeD6ZNbuYz1IavoaU1p8GkoTAECGdayVf
Qvvt5aP1jJK7uortJY8+qQ+KghcoNCnNa6BHewmF9U9j1GnBcn5bMuhIc1fh1x0D
jKoKiu+Pba7AlwwCy7pKM+YGPrFgkUrL1LsWt7VPqB2HhA7LdUAng0+qfOk+4lWJ
qdgcBPh8EZ0RZZWNGJMjsr7W5GMW4iNHnNmoNqw2zO1E9610R9dfs/kENqkv5yg9
Qt0lv7zGdD29e6epY87pUN/UQxHOlOUsMUuobMxqJ3qhmtE5NKidr7i6fXAR2qUc
lh+AT7EqhUCqu7Z1ztSdDaChfK7EDNTnh+vGRApjo4Mgy02dTRjv++RRsNfqvyYN
wL9ceJmTCxH4e5PaBGtTSlC6lz0B6+Cpzzz19E4N0LZ2zMEEuyvhIJYe2UMIgE7N
rqZbKzkVDrAAe4/EW1Y6pE6HAkl8OCC4DzU5Bum2QaKb8+ozsTYT6rTl00AL9ftG
L6wV3FVm6ZVavnT5kfdFFrox+iXsBZnONqA2KluS3u+SL+HqZXA=
=tihJ
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
apr-util, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143837@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Bastien Roucariès <rouca@debian.org> (supplier of updated apr-util package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 09 Aug 2026 18:26:22 +0200
Source: apr-util
Architecture: source
Version: 1.6.3-3+deb13u1
Distribution: trixie-security
Urgency: high
Maintainer: Debian Apache Maintainers <debian-apache@lists.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Closes: 1143837
Changes:
apr-util (1.6.3-3+deb13u1) trixie-security; urgency=high
.
* Non-maintainer upload on behalf of Apache Team.
(Closes: #1143837)
* Fix CVE-2025-49506:
Function apr_password_validate() was not constant-time with
regards to hashes or passwords comparisons, potentially leaking
their content via a side channel timing attack.
* Fix CVE-2026-32327:
A stack recursion attack against any library consumer
which parses XML from untrusted sources and uses the
apr_xml_quote_elem() function
* Fix CVE-2026-34191:
Improper Neutralization of Special Elements used
in an SQL Command (SQL Injection) vulnerability
in Apache Portable Runtime Utility via apr_dbd_oracle provider.
* Fix CVE-2026-34501:
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility redis client.
* Fix CVE-2026-34502:
Heap-based Buffer Overflow vulnerability in Apache Portable
Runtime Utility memcached client
Checksums-Sha1:
f7e142cf8d4d3c02942e513807a2b2413026bfe6 2572 apr-util_1.6.3-3+deb13u1.dsc
8c6293a787b69986ce43bc49c7c247d4ff5fc828 432692 apr-util_1.6.3.orig.tar.bz2
bc1f492a7e1e2b1468c23285c1d86f62f0dcbf31 348040 apr-util_1.6.3-3+deb13u1.debian.tar.xz
ac6ca17ec03273650e02ed4a0960db0c368a5c32 5888 apr-util_1.6.3-3+deb13u1_source.buildinfo
Checksums-Sha256:
1b1bc45ea8927794f1901e75a5415fff11625815b34fc4c071df89710c61f6e0 2572 apr-util_1.6.3-3+deb13u1.dsc
a41076e3710746326c3945042994ad9a4fcac0ce0277dd8fea076fec3c9772b5 432692 apr-util_1.6.3.orig.tar.bz2
5bd2179a2cd4ac4351286a107431111b738b8f0d1c8fa65022bef34b72629278 348040 apr-util_1.6.3-3+deb13u1.debian.tar.xz
4a676e49089e9c4d8768acdd945e962eb649f4b0d5a2f318c7d7e165ada8694f 5888 apr-util_1.6.3-3+deb13u1_source.buildinfo
Files:
5a4d8090fe2552bf7c3f53d06cba1eeb 2572 libs optional apr-util_1.6.3-3+deb13u1.dsc
b6e8c9b31d938fe5797ceb0d1ff2eb69 432692 libs optional apr-util_1.6.3.orig.tar.bz2
6d9ca0ac73b3a8eb9d9fc9c47a061e20 348040 libs optional apr-util_1.6.3-3+deb13u1.debian.tar.xz
99a0383372dd2ec153ee840df1387c65 5888 libs optional apr-util_1.6.3-3+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmp8fzIACgkQADoaLapB
CF9Eow/+MEHRdf3GNoP5hcp1rwcgmljmx3CLcNr5Rvkc9u8DJalB7fdu0SDVW6M/
KoayYJ1u3tzn6Ro0OYfmDnhDjIp59FA//2dkSGhHuhRYfpFdjGU6C0rGUaYzN1gW
Xl4nQnLFVWzMfuAuZLZSK1FJ5xp4tq+OrCHbOEd7bVv8iOPv9lN2iZBwLk1gouJG
OEBQvxREVxcoKyv3/RT6K5dO8lJoXwWnH3bkzCG11tSt2dWSksiABkc0v9Tg2x1c
vbZZ8oqn3WiDmA1f8cXQTGTXvjx3DGiyICGvjJm3mxYcXEGLFHaT7AOrXfKctCRt
JpefhxoVHyUf1jHDm0IBnoS31aGUy101gVnfYON9LEJPHraQRey9F7e1tB+p/a/T
mm/CzEizgH2cJmVo8G1Q3UfZ/xvE/ZUt3hojTT0rgBwy7bRrd8QbYra7A1+vkIfJ
EwJB1jJqYx/Kc5xU2pc3FakCJqoPx8cU6pI9qmdRGQNCZK87DhP9PYqJT8RM36T+
6/RkP+jcjpZa05vwG93DFmXJJOu0UwaayGZOcKwZcJQizebbL6b8ALY+9NB9urmy
Ne6+Oelt5QP/Xdee+nB4yM7b68ItONqcisY00uIUx/gAO98+gpp8PldI1oJ97PAM
WHLFtirzxSPMMO1ZW7DsVOeWfG+wZZb1cJTvopzUmXlPcGSHVGU=
=Lyar
-----END PGP SIGNATURE-----