Packages
- apr-util - Apache Portable Runtime Utility Library
Details
It was discovered that APR-util incorrectly performed password hash
comparisons in a way that was not constant-time.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2025-49506)
It was discovered that APR-util incorrectly handled recursive XML element
quoting. An attacker could possibly use this issue to cause applications
using APR-util to crash, resulting in a denial of service.
(CVE-2026-32327)
It was discovered that the APR-util Redis client incorrectly handled
certain network data, resulting in a heap-based buffer overflow. A remote
attacker could possibly use this issue to cause APR-util applications to
crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(
It was discovered that APR-util incorrectly performed password hash
comparisons in a way that was not constant-time.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2025-49506)
It was discovered that APR-util incorrectly handled recursive XML element
quoting. An attacker could possibly use this issue to cause applications
using APR-util to crash, resulting in a denial of service.
(CVE-2026-32327)
It was discovered that the APR-util Redis client incorrectly handled
certain network data, resulting in a heap-based buffer overflow. A remote
attacker could possibly use this issue to cause APR-util applications to
crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-34501)
It was discovered that the APR-util memcached client incorrectly handled
certain network data, resulting in a heap-based buffer overflow. A remote
attacker could possibly use this issue to cause APR-util applications to
crash or execute arbitrary code. (CVE-2026-34502)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
| Ubuntu Release | Package Version | ||
|---|---|---|---|
| 26.04 LTS resolute | libaprutil1t64 – 1.6.3-3ubuntu3.1 | ||
| 24.04 LTS noble | libaprutil1t64 – 1.6.3-1.1ubuntu7.1 | ||
| 22.04 LTS jammy | libaprutil1 – 1.6.1-5ubuntu4.22.04.3 | ||
| 20.04 LTS focal | libaprutil1 – 1.6.1-4ubuntu2.2+esm1 | ||
| 18.04 LTS bionic | libaprutil1 – 1.6.1-2ubuntu0.1+esm1 | ||
| 16.04 LTS xenial | libaprutil1 – 1.5.4-1ubuntu0.1~esm1 | ||
| 14.04 LTS trusty | libaprutil1 – 1.5.3-1ubuntu0.1~esm3 | ||
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.