Security Advisory Desk
unratedQCS priority 76/100Ubuntu

USN-8719-1: APR-util vulnerabilities

Several security flaws were found in the APR-util library used by Ubuntu. These issues could allow attackers to access sensitive information, crash applications, or even run malicious code remotely. Users of Ubuntu versions 18.04 LTS through 26.04 LTS should update their systems to fix these problems.

Published 3/9/2026, 12:35:55 pmVerified 6/9/2026, 3:24:39 pmRevision 1
Ubuntu unrated network security advisory visual

In plain language

What this advisory means

Several security flaws were found in the APR-util library used by Ubuntu. These issues could allow attackers to access sensitive information, crash applications, or even run malicious code remotely. Users of Ubuntu versions 18.04 LTS through 26.04 LTS should update their systems to fix these problems.

Technical explanation

How the issue affects the environment

APR-util contained multiple vulnerabilities: First, its password comparison did not use constant-time operations, enabling side-channel leaks (CVE-2025-49506). Second, recursively quoted XML elements were mishandled, causing denial-of-service crashes (CVE-2026-32327). Third and fourth, Redis and memcached clients processed certain network data unsafely, leading to heap-based buffer overflows, allowing remote attackers to crash applications or execute code (CVE-2026-34501, CVE-2026-34502). These affect Ubuntu 18.04 LTS through 26.04 LTS. Updates provide corrected versions to mitigate these flaws.

Operational impact

Why teams should care

Exploitation could lead to data leaks, application outages, or full system compromise. This risks service availability and data confidentiality, impacting organizational operations and trust.

Immediate action

Perform a standard system update to upgrade the apr-util packages to the versions that include these security fixes. For older versions, consider Ubuntu Pro subscription or ESM for extended security support.

Affected and fixed releases

Affected versionsUbuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, Ubuntu 26.04 LTS
Fixed versionsUbuntu 18.04 LTS libaprutil1 1.6.1-2ubuntu0.1+esm1, Ubuntu 20.04 LTS libaprutil1 1.6.1-4ubuntu2.2+esm1, Ubuntu 22.04 LTS libaprutil1 1.6.1-5ubuntu4.22.04.3, Ubuntu 24.04 LTS libaprutil1t64 1.6.3-1.1ubuntu7.1, Ubuntu 26.04 LTS libaprutil1t64 1.6.3-3ubuntu3.1

Temporary risk reduction

The official notice does not specify any workaround. Users should update packages promptly to mitigate risk.

Evidence and validation checklist

  • Ubuntu Security Notice USN-8719-1
  • Advisory publication date: 2026-09-03
  • Package versions listed for Ubuntu LTS releases
  • Descriptions for CVE-2025-49506, CVE-2026-32327, CVE-2026-34501, CVE-2026-34502

Authoritative reference

Ubuntu Security Notices

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source