-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jun 2026 12:55:53 +0200 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym libapache2-mod-md libapache2-mod-proxy-uwsgi Architecture: ppc64el Version: 2.4.67-1~deb12u3 Distribution: bookworm-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-01) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) libapache2-mod-md - transitional package libapache2-mod-proxy-uwsgi - transitional package Changes: apache2 (2.4.67-1~deb12u3) bookworm-security; urgency=medium . * Fix CVE-2026-49975 (HTTP/2 Bomb) The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it. Checksums-Sha1: e71982dfafc58f1281e38cd2703384cead5463a6 3507772 apache2-bin-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 3ec7dabd9ac4010d1692df94f15c7aa8a85f3c26 1463324 apache2-bin_2.4.67-1~deb12u3_ppc64el.deb 31b5ce5c53f5296f0cb35cbb49621adb222de491 323088 apache2-dev_2.4.67-1~deb12u3_ppc64el.deb d33a8a64997c7f6fbb8be2257550c199590391d2 3144 apache2-ssl-dev_2.4.67-1~deb12u3_ppc64el.deb a0834d6772bb59c9bbac5c95898d87fc9f481fa1 12796 apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 19c9898e920e7a685e367b8fc751f5a868573054 150756 apache2-suexec-custom_2.4.67-1~deb12u3_ppc64el.deb c71382916f4e60026feeddcd99c3cfcb7ff07669 11444 apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 2f2e760e11892cf426fe5ccf413463caff4a3fe3 148948 apache2-suexec-pristine_2.4.67-1~deb12u3_ppc64el.deb b9e8f912efcb5877ab97ee231cc56c9e9cc38ccf 119592 apache2-utils-dbgsym_2.4.67-1~deb12u3_ppc64el.deb fd71fcd8db5745ddc718c840c113a64a93406b43 218720 apache2-utils_2.4.67-1~deb12u3_ppc64el.deb 9c455a4d973712e549f5d01696d5d0ade63f02f3 11963 apache2_2.4.67-1~deb12u3_ppc64el-buildd.buildinfo 1eb9faf8871763a6a7ae00475636222505b7314e 231040 apache2_2.4.67-1~deb12u3_ppc64el.deb f1145354d0c2aa3909c8e5ab8bdc3b0b64a4674d 956 libapache2-mod-md_2.4.67-1~deb12u3_ppc64el.deb e5936cd9838f1dc7d261744dfda864ba8b8ee617 1136 libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_ppc64el.deb Checksums-Sha256: 1d9782ab4b8fe007d5f1f6160b0477ffb6c418c8b1b33bf23836f5485b832d50 3507772 apache2-bin-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 4384a9bebd29c7c8b7527f2d19dea06264e22ac0c90aedc67084a5cbf5dd2b84 1463324 apache2-bin_2.4.67-1~deb12u3_ppc64el.deb 2030f71b69f1846fca2b99e7a44d75375a93ce7b6c4c95cff232f74495072b38 323088 apache2-dev_2.4.67-1~deb12u3_ppc64el.deb dbac52a0d107e6a92a5466fb2efd453304518be83a45171a38d5f7ae09883e1b 3144 apache2-ssl-dev_2.4.67-1~deb12u3_ppc64el.deb ec11db18b98a98f8a31c72b94edf0f5564354bcfdb2e97d6e8b806982b759552 12796 apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 1ff2447909ccdb781da0d196508f778af94b848f20a7800bdb780b92c3ddcca8 150756 apache2-suexec-custom_2.4.67-1~deb12u3_ppc64el.deb 1e22e377b33b5e93acb734d7ded1615ea2315d188c4b502f3f9119006887e361 11444 apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 7693d04e78317c159f61a280ccc2d7c39bb1fba329ae4580846b2e6f46174612 148948 apache2-suexec-pristine_2.4.67-1~deb12u3_ppc64el.deb 7fab2619dc501a1d85ae3d91150333bb65d15d441226b281f9be3d52289cebbf 119592 apache2-utils-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 41e6abac0b7c8d98cb436ec35c4bb4b33f5a4b5106bfcf0e9ed4096da61f2535 218720 apache2-utils_2.4.67-1~deb12u3_ppc64el.deb afec5bf0c506c0d08cce77d3acf21af14ba1739cb8eeec88d3c406152e30fed7 11963 apache2_2.4.67-1~deb12u3_ppc64el-buildd.buildinfo 398faab3bcd4e0bc08a31e164bbbc06201fa1d9225d7a3577ba82189bd06b96b 231040 apache2_2.4.67-1~deb12u3_ppc64el.deb 4e943c202009eb15cc29574a7bed7ddf68bf7f2e645df551bb79125986d3b03f 956 libapache2-mod-md_2.4.67-1~deb12u3_ppc64el.deb 4b5c759e55ceaa7210cc62b81c7ff786f69679478ff4f1bee6ce26f64dbacbb9 1136 libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_ppc64el.deb Files: 28cb9b463e4fe84e58932d9f2cd6014f 3507772 debug optional apache2-bin-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 463b897787e7ed18cc496c4d2a161260 1463324 httpd optional apache2-bin_2.4.67-1~deb12u3_ppc64el.deb 2b02f370014737e72467b385e07015ac 323088 httpd optional apache2-dev_2.4.67-1~deb12u3_ppc64el.deb f1587721e185dc64d2c7093e0f6cfae9 3144 httpd optional apache2-ssl-dev_2.4.67-1~deb12u3_ppc64el.deb 8870e89db948a156d7afcb74b6898fc7 12796 debug optional apache2-suexec-custom-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 550827d375d9f93088aee8ea86a3924d 150756 httpd optional apache2-suexec-custom_2.4.67-1~deb12u3_ppc64el.deb d3dd229ae96a3454e5da974b43c98fcc 11444 debug optional apache2-suexec-pristine-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 080b680ba78b96f52a68b17360ed6c43 148948 httpd optional apache2-suexec-pristine_2.4.67-1~deb12u3_ppc64el.deb 63550435e65ea13dd4cdda4fabd61364 119592 debug optional apache2-utils-dbgsym_2.4.67-1~deb12u3_ppc64el.deb 1a60bd30a38a2fdd21ea322353654e91 218720 httpd optional apache2-utils_2.4.67-1~deb12u3_ppc64el.deb 9fdac65ec7e82b64f2205d6dc38f1ba2 11963 httpd optional apache2_2.4.67-1~deb12u3_ppc64el-buildd.buildinfo 89fbad4995165bede9d78c4f55d47baf 231040 httpd optional apache2_2.4.67-1~deb12u3_ppc64el.deb 817ee6313154002c4da22b4623ae01dd 956 oldlibs optional libapache2-mod-md_2.4.67-1~deb12u3_ppc64el.deb fe80c8ed69bde7629d8e92c5b49fc04c 1136 oldlibs optional libapache2-mod-proxy-uwsgi_2.4.67-1~deb12u3_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEDoRc43uRWMOoIqIgDNLUPhbmg7MFAmokEzwACgkQDNLUPhbm g7NaxRAAnlnQsFq8912F1Z8GlWxp8VLyaz27dcNkOsSQX9IlGzL2aHyagD7dRkj7 z8OzWWx89SIqddobVFTlYLlxzJyVVaoxp1lrAvgqUce5BoNJ2rj9CU4KcU1e2J8S 0zY5hGHjoZJY2pjLE0cYC10enj/Jv5ulWadGHlBGOVLUgSQnRRmzWPeCyZpuocw2 QhgzxgxjoaW7rBag5RceXveUiVmq/6g0dJ7jDaJZ+2TmCsid52GctttUXpDYRkzo txxYrwS4JwSiCmG4UhrMuyeVJDvk/rCBS2D4Op9V1r5rpIVZypI+XkSE3aff3y5R CD8JkZ1tk5foSkmZ4F4V2yNw9mcSHLU/4QbbznjgpJ0xPmmlz+koB1Nz+JQ06tcX OQFAl4epj3gyGTMb3yAdjJEeODhfnqmUtGaGzUMJNVWt+H3gP50mTS7lcgT5aLiQ et/ivSzxHXvwKKNSj2nJj+vBgETz6ZKWCm50Eg5gYW4pTyTkJ1tIxFdJDD43HW2q oW+qY4EQdyE/UCe55+/Kz7mzbWBxKnMxoC23G4PrQRQ48Ea39Mt0JdXMg/0vQwWI n9XbrnmixBtjdLm/9v+bBYi+XYdA+8Q5G8kt/VD9tBjfV2ahcIGcKkl9OQV0X6nQ +FpECp3Zo7dc5FbtH/WS3VxGZ6xHUEH8BbvO/V1de6dQyOkVoP8= =aEZE -----END PGP SIGNATURE-----