Apache Portable Runtime Utility: Heap buffer overflow in APR redis client
Published Aug 6, 2026
7.5
HIGHCVSS 3.1
EPSS 0.51%
Description
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.
This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.
Users are recommended to upgrade to version 1.6.4, which fixes the issue.
Affected products
-
- Version 1.6.0StatusaffectedConstraints<=1.6.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Portable Runtime Utility | unaffected |
|
No data.
Red Hat Enterprise Linux 10
apr-util-0:1.6.3-23.el10_2.1
Fixed · RHSA-2026:66392
Red Hat Enterprise Linux 8
apr-util-0:1.6.1-9.el8_10.1
Fixed · RHSA-2026:69113
Red Hat Enterprise Linux 9
apr-util-0:1.6.1-23.el9_8.1
Fixed · RHSA-2026:66341
Red Hat Hardened Images
apr-util-main-1.6.5-1.hum1
Fixed · RHSA-2026:58474
Red Hat Enterprise Linux 6
apr-util
Out of support scope
Red Hat Enterprise Linux 7
apr-util
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | apr-util-0:1.6.3-23.el10_2.1 | Fixed | RHSA-2026:66392 |
| Red Hat Enterprise Linux 8 | apr-util-0:1.6.1-9.el8_10.1 | Fixed | RHSA-2026:69113 |
| Red Hat Enterprise Linux 9 | apr-util-0:1.6.1-23.el9_8.1 | Fixed | RHSA-2026:66341 |
| Red Hat Hardened Images | apr-util-main-1.6.5-1.hum1 | Fixed | RHSA-2026:58474 |
| Red Hat Enterprise Linux 6 | apr-util | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | apr-util | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The impact of this vulnerability is rated as Moderate. Although the flaw involves a heap buffer overflow and the CVSS base score reflects an unauthenticated network vector, exploitation requires the attacker to control or compromise the Redis server that the application queries. An attacker cannot trigger this condition by sending data directly to the affected application — they must first be in a position to influence Redis responses, either by compromising the Redis backend or performing a man-in-the-middle attack on the connection. Additionally, the overflow does not result in arbitrary code execution; the observed impact is limited to a denial of service. This prerequisite significantly limits real-world exploitability.
Red Hat mitigation
Ensure that the Redis server used by the application is deployed in a trusted, network-segregated environment and is not accessible to untrusted parties. Where possible, configure authentication and TLS on the Redis connection to reduce the risk of a compromised or spoofed Redis server.
References (7)
- http://www.openwall.com/lists/oss-security/2026/08/06/11 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-34501 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2512073 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53917 Advisory
- https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv vendor-advisoryMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34501
- https://www.cve.org/CVERecord?id=CVE-2026-34501
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/08/06/11 | Mailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2026-34501 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2512073 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-53917 | Advisory | |
| https://lists.apache.org/thread/o8h6c7cq86fplxlnry6c3rn9x0ovq8mv | vendor-advisoryMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-34501 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-34501 |
Change history (0)
No recorded changes yet.