-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 05 Jun 2026 12:55:53 +0200 Source: apache2 Binary: apache2 apache2-bin apache2-bin-dbgsym apache2-dev apache2-ssl-dev apache2-suexec-custom apache2-suexec-custom-dbgsym apache2-suexec-pristine apache2-suexec-pristine-dbgsym apache2-utils apache2-utils-dbgsym Architecture: s390x Version: 2.4.67-1~deb13u3 Distribution: trixie-security Urgency: medium Maintainer: s390x Build Daemon (ziehrer) Changed-By: Bastien Roucariès Description: apache2 - Apache HTTP Server apache2-bin - Apache HTTP Server (modules and other binary files) apache2-dev - Apache HTTP Server (development headers) apache2-ssl-dev - Apache HTTP Server (mod_ssl development headers) apache2-suexec-custom - Apache HTTP Server configurable suexec program for mod_suexec apache2-suexec-pristine - Apache HTTP Server standard suexec program for mod_suexec apache2-utils - Apache HTTP Server (utility programs for web servers) Changes: apache2 (2.4.67-1~deb13u3) trixie-security; urgency=medium . * Fix CVE-2026-49975 (HTTP/2 Bomb) The bomb targets HPACK, HTTP/2's header compression scheme: one byte on the wire becomes one full header allocation on the server, repeated thousands of times per request. The hold is a zero-byte flow-control window that keeps the server from ever freeing any of it. Checksums-Sha1: 317c94052a8d5f1087e8d97b343e372de417ecef 3475632 apache2-bin-dbgsym_2.4.67-1~deb13u3_s390x.deb 0da9aa45aea7a038aefe768311ed75cb30d146f5 1379968 apache2-bin_2.4.67-1~deb13u3_s390x.deb 214bd0910bf7cba2f93c560d4a8d738f4195bb10 323092 apache2-dev_2.4.67-1~deb13u3_s390x.deb cdad7a78e4ea933f31f73bb36821d48383abc66f 3140 apache2-ssl-dev_2.4.67-1~deb13u3_s390x.deb 0fe439904dafe9d85be1d4c8b211185f36c0767e 12368 apache2-suexec-custom-dbgsym_2.4.67-1~deb13u3_s390x.deb a720a08b2fc97edb595aea3aa2fe357bfc8bb302 151368 apache2-suexec-custom_2.4.67-1~deb13u3_s390x.deb f76a2d37cba3c6d8541f9ab540e3dd657af3665e 11040 apache2-suexec-pristine-dbgsym_2.4.67-1~deb13u3_s390x.deb eddfa6b6166525d749433603f4c01cc99278adb4 149780 apache2-suexec-pristine_2.4.67-1~deb13u3_s390x.deb 6c8857a2493ebc9958418c09aaa2d49b762e4e32 117280 apache2-utils-dbgsym_2.4.67-1~deb13u3_s390x.deb 2e1b2ef45439af5db1d9b692b4ada688d7fe1fd6 217480 apache2-utils_2.4.67-1~deb13u3_s390x.deb 6dc7d0c693de82ae58d6f215dd9a66a29de57847 11744 apache2_2.4.67-1~deb13u3_s390x-buildd.buildinfo 2737f00c32c637154d0741b30b8a9635a8b8055a 226264 apache2_2.4.67-1~deb13u3_s390x.deb Checksums-Sha256: dba9ef337176db6a91e939d27a399d9a7606e4bc7e780ced9f3514113b80447d 3475632 apache2-bin-dbgsym_2.4.67-1~deb13u3_s390x.deb 8750c91dcb5ecc57458cb3b00fef9cb27eefc6b1cd2438ceb1f6357510c3747a 1379968 apache2-bin_2.4.67-1~deb13u3_s390x.deb 59ac4ebf8c36eb07e76848766930d03f4b516a556164ed25f4e48db253c1e179 323092 apache2-dev_2.4.67-1~deb13u3_s390x.deb 4faad7a242f81561e4223a58b881743b7587a13e1a6ae5b508ea40d82da45cc5 3140 apache2-ssl-dev_2.4.67-1~deb13u3_s390x.deb a7b192c9e2bed11856f64a2a7168c8f810cc818f9443ef7058aaf53f453dd25d 12368 apache2-suexec-custom-dbgsym_2.4.67-1~deb13u3_s390x.deb d975bd3e2b6c05ee10e0b964bef5a1985b7c130020e4b8a553eb1b45f24dafc7 151368 apache2-suexec-custom_2.4.67-1~deb13u3_s390x.deb 3dca9cb9fe5e29942061cb3943e993478e01438d1a9222e2d00bd4844c9f5a1a 11040 apache2-suexec-pristine-dbgsym_2.4.67-1~deb13u3_s390x.deb 7f00481e8bba0e063d6555f3f72fe1b43c0cd53f5d6208fcb8487300a9573363 149780 apache2-suexec-pristine_2.4.67-1~deb13u3_s390x.deb 84c30f74c9145418c9444a21b431d490abe92ddffc2308c15cce8eb5fa691ef2 117280 apache2-utils-dbgsym_2.4.67-1~deb13u3_s390x.deb 597cfe1ac9b167111ce0f6da416acb8d25f7eb801d6ecc30e5704f77b367dc0c 217480 apache2-utils_2.4.67-1~deb13u3_s390x.deb e73ad69005f58f6f8be9a81c74a47f0242fd4f15823cae0ccebc3ad5b561c734 11744 apache2_2.4.67-1~deb13u3_s390x-buildd.buildinfo ffa38a5bbc2bdb148dacfc8f7d393f157c3c9d78b42424278fce43ff3e1a1b61 226264 apache2_2.4.67-1~deb13u3_s390x.deb Files: db754f854bf4535471d648ea0b04458b 3475632 debug optional apache2-bin-dbgsym_2.4.67-1~deb13u3_s390x.deb 5b1f524af5994c83921736334266101b 1379968 httpd optional apache2-bin_2.4.67-1~deb13u3_s390x.deb 70a93769b19a1a411a2e8efb1c623f46 323092 httpd optional apache2-dev_2.4.67-1~deb13u3_s390x.deb 5aff49943ce6b6f65a5010b328ff22bb 3140 httpd optional apache2-ssl-dev_2.4.67-1~deb13u3_s390x.deb f577e05b2fb66c82344b2827b5769aaf 12368 debug optional apache2-suexec-custom-dbgsym_2.4.67-1~deb13u3_s390x.deb 0b94b5f3011e59ae000475f7427b5c95 151368 httpd optional apache2-suexec-custom_2.4.67-1~deb13u3_s390x.deb f58cd41516adda680abe3c34816163ab 11040 debug optional apache2-suexec-pristine-dbgsym_2.4.67-1~deb13u3_s390x.deb 2fa4dc4f0cfd4f3f3bcedca60d0445de 149780 httpd optional apache2-suexec-pristine_2.4.67-1~deb13u3_s390x.deb e092895e866bc3809b27ae1a2427b0b7 117280 debug optional apache2-utils-dbgsym_2.4.67-1~deb13u3_s390x.deb d020ca34ae17f06d3aea6e6f4054ed06 217480 httpd optional apache2-utils_2.4.67-1~deb13u3_s390x.deb b8fa44d1b548ad1cce30dcff2e4f902d 11744 httpd optional apache2_2.4.67-1~deb13u3_s390x-buildd.buildinfo 306b1ef68712b1bf1d28f220d481119d 226264 httpd optional apache2_2.4.67-1~deb13u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmokIIsACgkQMWUFebkH noSNixAAn5jdGqDZZ+A2jXqBHoFyDQBjNLwk3nqWdW+WyluE81lxn/wbrSsLaYFv W+sLYK1w0YdC+nHpQKyf3Yh6BCR0bA3y/B45kvAbWHt0Z7Fcw3o3stm4o2nB0mJq 3k5DCNvzBxmV+iDm5RMP+LrxD581o0F/0RhINC8HOa35t5d3WaRv+RrHaYHTdtBv P3uBU5rSBhDSA2KTh4ctlwM/+6A5CukE3RPiZ+rTnGIBCqELklTJFG46XYZIx1m/ b1b8TjE9kJBJUzvqEN4CtnNWji9yoJ7KyTMr0CHGZ0sMkLFJxv2rodn9H/9tvFku aL8CPYAI7ifL4fqT+83fE3hDrh+HhZL93hAveVVGHxVyTCsGd7ivsdixfdPZrdhn HB7s8Ez3QYZnR5jRqWAUfYKKRwKFEgSzrZzdoaYUiITD0DO27CEkOKqMx+4nXUsI s4OqC3EPyR3MByAfC3McymxoJWWFW8lBsGgVQ5NEHGeGpYCEN7MmHcUmkN7KTAHf c5/6FZ3DrD7m6yGlAzbNiLk4//ORshAZYY9VXQ0Xh34XL1lQLQbSsK9b0U30p9AG J2olaUs6obqbwolNuNOKWTN9hA5JUDd3yWXt0+tw1ruQfuwFjOVdGRv+HPhhapmt YDAo65z/Hpm5975GuZA7seAlV6fT3blQAlvhFtLP0i1YPlN8xjM= =oFnU -----END PGP SIGNATURE-----