ELA-1441-1 modsecurity-apache security update

denial of service

2025-05-29
Packagemodsecurity-apache
Version2.8.0-3+deb8u3 (jessie), 2.9.1-2+deb9u3 (stretch), 2.9.3-1+deb10u3 (buster)
Related CVEs CVE-2025-47947


DoS with sanitiseMatchedBytes has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security.



For Debian 10 buster, these problems have been fixed in version 2.9.3-1+deb10u3.

For Debian 8 jessie, these problems have been fixed in version 2.8.0-3+deb8u3.

For Debian 9 stretch, these problems have been fixed in version 2.9.1-2+deb9u3.

We recommend that you upgrade your modsecurity-apache packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.