-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jun 2026 12:55:53 +0200 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: mipsel Version: 2.4.67-1~deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: mipsel Build Daemon (mipsel-osuosl-04) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.67-1~deb12u3) bookworm-security; urgency=medium . * Fix CVE-2026-49975 (HTTP/2 Bomb) The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it. Checksums-Sha1: a8cdbfb7c72d8a9e6d84df52cd11f06b2d9199e1 3500020 apache2-bin-dbgsym_2.4.67-1~deb12u3_mipsel.deb 600f368aee980d5ad951f834168a7c6ef39052de 1264836 apache2-bin_2.4.67-1~deb12u3_mipsel.deb 6163062d2be29a3e10d28b2631678823402055d8 323096 apache2-dev_2.4.67-1~deb12u3_mipsel.deb 9d4fe29548dff8f2ab75c8b9bf4c3beb4ecf9c24 3144 apache2-ssl-dev_2.4.67-1~deb12u3_mipsel.deb 5efb5c140f821d86d2d4478ff8905714eec20504 12628 apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_mipsel.deb 873d1145eb978c2993207b49372dbafff5b3731a 150196 apache2-suexec-custom_2.4.67-1~deb12u3_mipsel.deb e876a9f6a11be21ccadd283c675b19e6d81c631d 11348 apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_mipsel.deb 77dab49f4d52761df8e45fa544746b3c909c5f15 148656 apache2-suexec-pristine_2.4.67-1~deb12u3_mipsel.deb b986272185ffad82c9908103c5200dad5a77242e 120876 apache2-utils-dbgsym_2.4.67-1~deb12u3_mipsel.deb a6d5713da4ea3a84a1c2c344095f1cd1b180aa1d 221452 apache2-utils_2.4.67-1~deb12u3_mipsel.deb f92a63b220db25fc86dbeb355081a88e43358ff7 11699 apache2_2.4.67-1~deb12u3_mipsel-buildd.buildinfo 205516015725f482116eea1cd71b5078e9442da3 231044 apache2_2.4.67-1~deb12u3_mipsel.deb f5bfafbccc34275e92791834e54cb24f4748816c 956 libapache2-mod-md_2.4.67-1~deb12u3_mipsel.deb 00e1ef26a5e58e4fea9a96ee3e514b7d738701d2 1136 libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_mipsel.deb Checksums-Sha256: b5522db46655d0c0e7377af883338c67947610f19a0c147f07fde8c88f60b08e 3500020 apache2-bin-dbgsym_2.4.67-1~deb12u3_mipsel.deb 3303c695e82819f0a3767f48c8f816925cee08f23dce6240b672edf2f5ec1124 1264836 apache2-bin_2.4.67-1~deb12u3_mipsel.deb e77e55b5e212357a9342c29e18314e22c63d07459ba3d485cf6001eadc19f8ea 323096 apache2-dev_2.4.67-1~deb12u3_mipsel.deb 0a12e7d1b8942f3a7c708035fbe997a2edecf052b8d147e39ca2fd1cc3fae026 3144 apache2-ssl-dev_2.4.67-1~deb12u3_mipsel.deb 764eb81eb1d208d41ba00aa24a3885fcf5e4367163a0d04f5b18aaba036fbce2 12628 apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_mipsel.deb b24cac722094095b0fbb5f099f928b16d506befe247656891376cefe2bfc7fe0 150196 apache2-suexec-custom_2.4.67-1~deb12u3_mipsel.deb 5eea59205e2672155c5dca7bbab73ef95b66f48adf86f97c672bfd0c4ce26055 11348 apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_mipsel.deb c6f4fc492529cbfb5a870c4f76f403e04133c5f8c2a96d2532cde839290d3163 148656 apache2-suexec-pristine_2.4.67-1~deb12u3_mipsel.deb ee35b3d279b7a9d8be5d64483f4bd95a43db0454859baedcf3b6d4483e2b3030 120876 apache2-utils-dbgsym_2.4.67-1~deb12u3_mipsel.deb ccd7ae32a24ff38e7fe5b0dc0da05b63ab10daadf312e77f7c5066f676058276 221452 apache2-utils_2.4.67-1~deb12u3_mipsel.deb 289dc42e7369461144f8460feeb6d558b65cbb73d5273966dc8a9a96c0c9164e 11699 apache2_2.4.67-1~deb12u3_mipsel-buildd.buildinfo 79f443c2d296efaf70b922331db144c87bca7d0f03f4ee3dfe1174e5b8a8685f 231044 apache2_2.4.67-1~deb12u3_mipsel.deb fbf864dcdb2f816c805673b7ea3f2bc795af61840f3bf243e150e7a5428e7eff 956 libapache2-mod-md_2.4.67-1~deb12u3_mipsel.deb 52ba02619e661d4fe4fc1fefbf8493149f089ec3f8b0b02e1a12fe21c3bd8497 1136 libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_mipsel.deb Files: f48f40d9d434f31e8ca6efcb0f42099d 3500020 debug optional apache2-bin-dbgsym_2.4.67-1~deb12u3_mipsel.deb 80ad28da0ded7207923006ba7dbd9eb5 1264836 httpd optional apache2-bin_2.4.67-1~deb12u3_mipsel.deb d6b348002b4b910335bb4eeb32b0865e 323096 httpd optional apache2-dev_2.4.67-1~deb12u3_mipsel.deb 1e3deb1a990949b979d26477ed74bc48 3144 httpd optional apache2-ssl-dev_2.4.67-1~deb12u3_mipsel.deb 15c48c7e0791780bd6d0c7e107d97c77 12628 debug optional apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_mipsel.deb cf7a89524896c1f86a3d30066e07c175 150196 httpd optional apache2-suexec-custom_2.4.67-1~deb12u3_mipsel.deb 0b5962a22a0b02dcbf12173f4041867f 11348 debug optional apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_mipsel.deb b715e04e5ae56c660cbda284017fb80f 148656 httpd optional apache2-suexec-pristine_2.4.67-1~deb12u3_mipsel.deb c42066c3ffaf5bb8f86b7603c7ae4a43 120876 debug optional apache2-utils-dbgsym_2.4.67-1~deb12u3_mipsel.deb 91ea38ec6f12504324d671711ebb9961 221452 httpd optional apache2-utils_2.4.67-1~deb12u3_mipsel.deb 29fd465f7b4c8616e3a039839042612f 11699 httpd optional apache2_2.4.67-1~deb12u3_mipsel-buildd.buildinfo 0e2bfae092e915b7b1adff8847368a93 231044 httpd optional apache2_2.4.67-1~deb12u3_mipsel.deb 58b72061197219a2e4745e2a3b620e81 956 oldlibs optional libapache2-mod-md_2.4.67-1~deb12u3_mipsel.deb 0748742aa18c6270b50963346ac9532c 1136 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_mipsel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEyYUQCyzsgu940OiVpwP2OD8jZaoFAmokFHsACgkQpwP2OD8j Zap5og/9HwS71fRHSGe+vzvtrJ/Q3qRw8eJxdmt/NggghRfvWYU4t51fi0m+wy4U SBhFpsIymLjnLE/gI51nZ51huoqdsTDTAIfuoiBVZXmKe7XA/XQmDj2rAt+fBnXj BM33OI1XdotOI6Oor5pKKrTWww/HUCmMsIaX7NEQT3oQ62piYzCIixz0e3fIEjWJ xcdkfKIRHFFk30xq/fzJCYVdLrWPVbWWQqz0rPdNdRLb33T5kv5cZOB39xbQQUgd kJ9fbhxMKOuZbYS8xIfYEDHRDEzuFHPMNRNPXAo6AVoR0dDPdZwczwbpYxS7SOc3 2VmF5bnSJmhuUGl4BE6tXtMCkkECf8du2S1lp2vrpgalx+FaFmn3hWd8QIx8UU5a h6bsHKZqMdxi9NaZbeE2l0H/UDdnmIofLgkaXCqCyghJPlvH818Ds9Tr/rbuMzZs 898yeRYHww8hI2Erzc3Q5xpG/jHTgtHnwGtKCMYM5HHUzoabXG8RvRq98dxMooGi Z7qhO/h7xxXjw718Km73Re3CNmM/Eeq5xEpeyu0UmYvxhkP3HRr+3PquFcQHPdDa hIvq+NpMvrUgmLAru8OeTGn518rw7yMsFNmo67eO5f0XmooHI9l/eRauTRxpXQBI x7+fYM6+JohnkgT7c2QbAA67yset+x+rx+QbIp9aFV+XEH/M46Q= =4CP9 -----END PGP SIGNATURE-----