<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.]]></title><description><![CDATA[<p>DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet.</p><p>Me: Thanks! Are your distro repos updated to contain the patched version?</p><p>DO: lol no</p><p>[Edit: to be fair, this is Debian's fault, not DOs (see screenshot). At least DO told me!]</p><p>[Edit 2: that specific vuln was quietly fixed on Debian specifically well before this version?? Would be advisable for them to have said that now? <br /><a href="https://infosec.exchange/@tychotithonus/116527548611779862"><span>https://</span><span>infosec.exchange/@tychotithonu</span><span>s/116527548611779862</span></a> ]</p><p><a href="https://infosec.exchange/tags/CVE_2026_23918" rel="tag">#<span>CVE_2026_23918</span></a></p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/524/985/539/367/532/original/e94a9ed20d0d613b.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/c42ab73c-6f13-4484-83e0-c079ed527776/digitalocean-hey-that-apache-vuln-thing-needs-upgrade-on-your-droplet.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 09:35:27 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/c42ab73c-6f13-4484-83e0-c079ed527776.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 06 May 2026 01:02:25 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 14:46:45 GMT]]></title><description><![CDATA[<p><span><a href="/user/gnomon%40mastodon.social" rel="nofollow noopener">@<span>gnomon</span></a></span> it's in the blog post. Eissing shows the timeline</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116528172620746616</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116528172620746616</guid><dc:creator><![CDATA[tychotithonus@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 14:46:45 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 13:53:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> do you happen to have a link to the info about Debian's .66 already having a fix for this issue?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/gnomon/statuses/116527964422881173</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/gnomon/statuses/116527964422881173</guid><dc:creator><![CDATA[gnomon@mastodon.social]]></dc:creator><pubDate>Wed, 06 May 2026 13:53:49 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 13:32:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> either way:</p><p>"Unpacking apache2 (2.4.67-1~deb12u1) over (2.4.66-1~deb12u2) ..."</p>]]></description><link>https://board.circlewithadot.net/post/https://social.ridetrans.it/users/Andres4NY/statuses/116527878865607965</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.ridetrans.it/users/Andres4NY/statuses/116527878865607965</guid><dc:creator><![CDATA[andres4ny@social.ridetrans.it]]></dc:creator><pubDate>Wed, 06 May 2026 13:32:03 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 12:27:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/andres4ny%40social.ridetrans.it" rel="nofollow noopener">@<span>Andres4NY</span></a></span> Parent post updated, apparently CVE-2026-23918 was fixed much earlier?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116527625503609267</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116527625503609267</guid><dc:creator><![CDATA[tychotithonus@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 12:27:37 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 07:11:11 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> yeah, that thing.</p><p>To my knowledge, the debian 2.4.66 packages already contain the fix. Which they could not link to the CVE as that was not available at the time.</p><p>"Responsible disclosure" strikes again.</p>]]></description><link>https://board.circlewithadot.net/post/https://chaos.social/users/icing/statuses/116526381249682303</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://chaos.social/users/icing/statuses/116526381249682303</guid><dc:creator><![CDATA[icing@chaos.social]]></dc:creator><pubDate>Wed, 06 May 2026 07:11:11 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 03:51:12 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> I just love the Debian security tracker, they manage the flood so good <a href="https://security-tracker.debian.org/tracker/CVE-2026-23918" rel="nofollow noopener"><span>https://</span><span>security-tracker.debian.org/tr</span><span>acker/CVE-2026-23918</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://zusammenkunft.net/users/eckes/statuses/116525594892423811</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://zusammenkunft.net/users/eckes/statuses/116525594892423811</guid><dc:creator><![CDATA[eckes@zusammenkunft.net]]></dc:creator><pubDate>Wed, 06 May 2026 03:51:12 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 01:30:33 GMT]]></title><description><![CDATA[<p><span><a href="/user/andres4ny%40social.ridetrans.it" rel="nofollow noopener">@<span>Andres4NY</span></a></span> Ah, thanks - I was just going to start asking!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116525041842115449</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116525041842115449</guid><dc:creator><![CDATA[tychotithonus@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 01:30:33 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 01:29:39 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> (Wasn't my decision, but I'm guessing they're a bit twitchy about .67 since the last "bugfix" apache release had a pretty serious regression: <a href="https://tracker.debian.org/news/1725501/accepted-apache2-2466-1deb13u2-source-into-proposed-updates/" rel="nofollow noopener"><span>https://</span><span>tracker.debian.org/news/172550</span><span>1/accepted-apache2-2466-1deb13u2-source-into-proposed-updates/</span></a> )</p>]]></description><link>https://board.circlewithadot.net/post/https://social.ridetrans.it/users/Andres4NY/statuses/116525038290459972</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.ridetrans.it/users/Andres4NY/statuses/116525038290459972</guid><dc:creator><![CDATA[andres4ny@social.ridetrans.it]]></dc:creator><pubDate>Wed, 06 May 2026 01:29:39 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 01:27:04 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> make sure you have (old)stable-proposed-updates enabled, it's going in that way rather than through stable-security.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://tracker.debian.org/news/1749045/accepted-apache2-2467-1deb13u1-source-into-proposed-updates/" title="Debian Package Tracker">
<img src="https://tracker.debian.org/static/img/logo.png" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://tracker.debian.org/news/1749045/accepted-apache2-2467-1deb13u1-source-into-proposed-updates/">
Debian Package Tracker
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://tracker.debian.org/news/1749045/accepted-apache2-2467-1deb13u1-source-into-proposed-updates/" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://tracker.debian.org/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(tracker.debian.org)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/post/https://social.ridetrans.it/users/Andres4NY/statuses/116525028117717775</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.ridetrans.it/users/Andres4NY/statuses/116525028117717775</guid><dc:creator><![CDATA[andres4ny@social.ridetrans.it]]></dc:creator><pubDate>Wed, 06 May 2026 01:27:04 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 01:04:34 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> edge first?  Lol</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/noplasticshower/statuses/116524939640245288</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/noplasticshower/statuses/116524939640245288</guid><dc:creator><![CDATA[noplasticshower@infosec.exchange]]></dc:creator><pubDate>Wed, 06 May 2026 01:04:34 GMT</pubDate></item><item><title><![CDATA[Reply to DigitalOcean: Hey that Apache vuln thing needs upgrade on your droplet. on Wed, 06 May 2026 01:03:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/tychotithonus%40infosec.exchange">@<span>tychotithonus</span></a></span> that's fine.</p><p>They aren't gonna patch the hypervisors either.</p>]]></description><link>https://board.circlewithadot.net/post/https://weird.autos/users/rootwyrm/statuses/116524934012155781</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://weird.autos/users/rootwyrm/statuses/116524934012155781</guid><dc:creator><![CDATA[rootwyrm@weird.autos]]></dc:creator><pubDate>Wed, 06 May 2026 01:03:08 GMT</pubDate></item></channel></rss>