CVE-2025-49506 @ morris
Status
not_applicable
Priority
7.5
Match score
4.0
Risk
InfoLeak
Remote
priv:user
CVSS
7.5 HIGH
Reason
cpe: apr-util; pkgs: apr-util, apr-util-devel; version: in-range: apr-util-1.5.2-6.el7_9.1; risk:info_disclosure
Created
2026-08-08T10:15:18Z
Updated
2026-08-22T10:16:17Z
Closed
2026-08-08T16:35:42Z
Package interrogation (copy)
Run on the host — click to copy a command. RPM
| Package | Commands |
|---|---|
| apr-util-1.5.2-6.el7_9.1 | |
| apr-util-devel |
Inventory lookup
Search package inventory across systems, then return here. Create a ticket on systems the matcher missed.
Suggestions: apr-util · apr-util-devel
| System | Matches | Ticket for CVE-2025-49506 | |
|---|---|---|---|
| morris | ea-apr-util-devel 1.6.5 | not_applicable open |
Same product CVEs in your queue
Other tickets that look like the same product (from match reason). Relate them here to triage this CVE as the primary.
| CVE | CVSS | KEV | Systems | Status | Matched | Already related | |
|---|---|---|---|---|---|---|---|
| CVE-2026-32327 | 9.1 | morris, mufasa | affects | apr-util | — | ||
| CVE-2026-34502 | 7.5 | morris, mufasa | not_applicable | apr-util | → CVE-2026-32327 | ||
| CVE-2026-34501 | 7.5 | morris, mufasa | not_applicable | apr-util | → CVE-2026-32327 |
Related CVE (same fix)
This CVE is subordinated to primary CVE-2026-32327 — same product as CVE-2026-32327
Host OS / kernel
OS
CloudLinux release 7.9 (Boris Yegorov)
(7.9)
· cloudlinux
Arch
x86_64
kernel_release
uname -r → 3.10.0-962.3.2.lve1.5.89.el7.x86_64kernel_version
uname -v → #1 SMP Thu Jul 9 15:55:31 UTC 2026For Linux kernel CVEs, kernel_version (Debian packaging / build string) often decides fixed vs not; kernel_release is used for upstream NVD range compares.
Same CVE on other hosts
Open the ticket for this CVE on another system.
| System | Status | Priority | Updated | |
|---|---|---|---|---|
| mufasa | not_applicable | 7.5 | 2026-08-22T10:16:17Z | Open |
Description
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue.
Determination
Related to primary CVE-2026-32327: same product as CVE-2026-32327
Update status
Add note only
Mitigation log
2026-08-08T16:35:42Z — not_applicable
Related to primary CVE-2026-32327: same product as CVE-2026-32327
References
- https://lists.apache.org/thread/2v8o3bj9pb7lfcr57bdnjg9xfkj04mg5
- http://www.openwall.com/lists/oss-security/2026/08/06/8
NVD: CVE-2025-49506