-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jun 2026 12:55:53 +0200 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: armhf Version: 2.4.67-1~deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: armhf Build Daemon (arm-conova-03) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.67-1~deb12u3) bookworm-security; urgency=medium . * Fix CVE-2026-49975 (HTTP/2 Bomb) The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it. Checksums-Sha1: 9ab236554b3b5966815c4daa25f993f61515b986 3358452 apache2-bin-dbgsym_2.4.67-1~deb12u3_armhf.deb 02f9c1486d50da0bbce96e49d1a9a15ceb34aab8 1222920 apache2-bin_2.4.67-1~deb12u3_armhf.deb 20395040a9767b7b7f665e223a91c78f06a8d050 323104 apache2-dev_2.4.67-1~deb12u3_armhf.deb 27fb2e54e48f0425e197ac87188180c17f5a1b01 3140 apache2-ssl-dev_2.4.67-1~deb12u3_armhf.deb 2062770244db7377a16bd1053c826ce9edf606c8 12264 apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_armhf.deb 9df098fd6596561b01a979ee6b9cc39b32737855 149768 apache2-suexec-custom_2.4.67-1~deb12u3_armhf.deb 7824afd84ad48f0bfb40a49edc299a9044422155 11028 apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_armhf.deb 811a2bb86cc7db0c38c41a199b75dd4b33153ebf 148300 apache2-suexec-pristine_2.4.67-1~deb12u3_armhf.deb bd29ec8271e4a8203012daf3374e3a016b52c809 118356 apache2-utils-dbgsym_2.4.67-1~deb12u3_armhf.deb 9605514833e7fa2a37706ab6af289da843e32fc0 216252 apache2-utils_2.4.67-1~deb12u3_armhf.deb 828a27d6171f763fb3cffc5944cfbd4ab0a4d9da 11744 apache2_2.4.67-1~deb12u3_armhf-buildd.buildinfo 351178a2fda143fb5096dce87f801668408927ae 231036 apache2_2.4.67-1~deb12u3_armhf.deb 9a69c1c0853587ec3a1460626ec63229c9b7ef80 956 libapache2-mod-md_2.4.67-1~deb12u3_armhf.deb be066563ba3ddfddba39f3bd5c5969e5c89ce81a 1136 libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_armhf.deb Checksums-Sha256: 4ee2b030c550730cee0e1341127d8f156ec42a180e94dcd1b5690f248b7715ad 3358452 apache2-bin-dbgsym_2.4.67-1~deb12u3_armhf.deb a337db9bbff15eaf5790a3758b1e0053b062dc81ea4b4056b853ebe673b64fa0 1222920 apache2-bin_2.4.67-1~deb12u3_armhf.deb 4c3dc57af40fc8c7d84e2bc46ec26f8dd8fc369621c3a91d70af67d6d1836a85 323104 apache2-dev_2.4.67-1~deb12u3_armhf.deb f9c9a9ee6091705ed9230a967973a157b880a862e75bba7527b1e5f3214720a5 3140 apache2-ssl-dev_2.4.67-1~deb12u3_armhf.deb 3c1124d0234263e702cc07eefd9ec7d1213d9d60655ea3e0486b24e885219024 12264 apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_armhf.deb a158710ad39199e3ab7452ca72c4750538357d117355cf107a1f9e94ad21d910 149768 apache2-suexec-custom_2.4.67-1~deb12u3_armhf.deb bfce5f75305f7b22c63503f16bfbc3ab8216ee1777b00f475562f705952be2f2 11028 apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_armhf.deb 19c32c1878f0ecd82ee8a38182909538d3ee4457902705aeeb4fcc57051193a5 148300 apache2-suexec-pristine_2.4.67-1~deb12u3_armhf.deb b24876f204d9ed35611e8302c23298b164a7da3aed7fb5a29f462303c7e141ac 118356 apache2-utils-dbgsym_2.4.67-1~deb12u3_armhf.deb 0b29d3a1d52da8c8a429a1847eb6d387b2ca8a55103b74a7bd0333289738655b 216252 apache2-utils_2.4.67-1~deb12u3_armhf.deb 68eede4fb5a8f3ecba1a626fa4b1795c5aa3500c5f490277b3f84d1789d57cea 11744 apache2_2.4.67-1~deb12u3_armhf-buildd.buildinfo 00c9821de791b8c3a1745cb31f1adcda9fa5341af42fe40738c10e187d6b2935 231036 apache2_2.4.67-1~deb12u3_armhf.deb 690f644e84a329d3fb139b37fc742591f52385e77738301e011d2b004c2e3434 956 libapache2-mod-md_2.4.67-1~deb12u3_armhf.deb e20e5879b630cbd0169565bdbbd195ed50b8da44ef8b5cc6f2aef88cf4d98782 1136 libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_armhf.deb Files: 1e558175bf462411eaa498b1c1afe0eb 3358452 debug optional apache2-bin-dbgsym_2.4.67-1~deb12u3_armhf.deb 008dff587eb66a292b31f2495a8904e4 1222920 httpd optional apache2-bin_2.4.67-1~deb12u3_armhf.deb 8e796a3fdfe994849251c3d6cb50e2a0 323104 httpd optional apache2-dev_2.4.67-1~deb12u3_armhf.deb c442cbbf6be1d6d6cfaf743d609be3c2 3140 httpd optional apache2-ssl-dev_2.4.67-1~deb12u3_armhf.deb a6e3ece07b7b4454d83dc0299d1538f9 12264 debug optional apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_armhf.deb dedf094decb16cd415b5622d974b152d 149768 httpd optional apache2-suexec-custom_2.4.67-1~deb12u3_armhf.deb 0854c960011700f22972f599d482b090 11028 debug optional apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_armhf.deb 6cf771d47a46accdd3d61e29032f9813 148300 httpd optional apache2-suexec-pristine_2.4.67-1~deb12u3_armhf.deb f0fa20fd0e238a9f1cd9d3aade31b63a 118356 debug optional apache2-utils-dbgsym_2.4.67-1~deb12u3_armhf.deb 7b7d6ef95934db9062151dfd7b2219ce 216252 httpd optional apache2-utils_2.4.67-1~deb12u3_armhf.deb 3e3fd478de5891d2984c16baf27d2953 11744 httpd optional apache2_2.4.67-1~deb12u3_armhf-buildd.buildinfo 5315d245a83b083a99898cd5ef3f8b94 231036 httpd optional apache2_2.4.67-1~deb12u3_armhf.deb f59e9d86c917a4113bfd8419adc82534 956 oldlibs optional libapache2-mod-md_2.4.67-1~deb12u3_armhf.deb 83fcdccacb4f7952efacade564dbc85a 1136 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElFiH1oZRZh1t4FSiXVp1sEH/1mIFAmokEw0ACgkQXVp1sEH/ 1mIXFA//V5E2e7yahjs6C2cGOYoPOGDsw1FJG/YrGhSyEBSqpuWR1oYO3qxrKPNp 0xpKZXqCOT6oQETCpmuX3ShEaKg8BRz0FRMm//xk9NSkm2NH/wvGYZTHEzP+ea8/ Fxz25MslgZPH0mlbgErF0BuSpWiacy3ZtCVM+c5CEarP/Jz6p9OyLg8F+m8PofSy S1r51+qvUwkmlGcO+w46VuvO0J2A+H8RXcfAmMNwOd0XrSeTXQYK4isiuh5rGU93 4Iq0tBJwjs2d0uvshn1JIpJ7sPm+D+yRBt4XRLhYYrzY5y2pgLjRn4KVDuJ8gDVF uNHuesES938aviIATEbjLRcEalFpxof9T1uRXREnvaj52RfKhR4VqwiewzfGdyas rUcQJZtWfsk3YraYiimLNCNopAWGWdrbG3tArVj/tGWRxYiGNgRrycqPjlEapA/k w8yZ6OM+mY0rfCTmPxe0pqPZUuqesSj0UjDc/7ybto4tpVq5n3TmC0zBXJ+Ockk0 jpphanovklOnGTrpMF970MDUnRa390IjQNtE/yrLhwdvUdr0UIV1SnIw1w8HWP1M a/eWxve7KmeTl3Ce6G5eU5WkSRxmcyKdO/QpuWclPqKBv9JrXTS/UhO+XeNy5osS rJyLFkQ813Rk1o+RJTqtHveL7uwHj//snOSycXGQBXiVzTatncs= =fy8N -----END PGP SIGNATURE-----