ELA-1823-1 apr-util security update

multiple vulnerabilties

2026-09-11
Packageapr-util
Version1.5.4-3+deb9u2 (stretch)
Related CVEs CVE-2025-49506 CVE-2026-32327 CVE-2026-34191 CVE-2026-34502


Several vulnerabilities were discovered in apr-util, the Apache Portable Runtime Utility library, which could result in denial of service or potentially the execution of arbitrary code.



For Debian 9 stretch, these problems have been fixed in version 1.5.4-3+deb9u2.

We recommend that you upgrade your apr-util packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.