ELA-1453-1 modsecurity-apache security update

denial of service

2025-06-09
Packagemodsecurity-apache
Version2.8.0-3+deb8u4 (jessie), 2.9.1-2+deb9u4 (stretch), 2.9.3-3+deb11u4~deb10u1 (buster)
Related CVEs CVE-2025-48866


DoS with sanitiseArg/sanitizeArg has been fixed in modsecurity-apache, a module for the Apache webserver to tighten Web application security.



For Debian 10 buster, these problems have been fixed in version 2.9.3-3+deb11u4~deb10u1.

For Debian 8 jessie, these problems have been fixed in version 2.8.0-3+deb8u4.

For Debian 9 stretch, these problems have been fixed in version 2.9.1-2+deb9u4.

We recommend that you upgrade your modsecurity-apache packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.