Multiple security vulnerabilities have been identified in Apache Portable Runtime Utility (apr-util), which could result in denial of service or potentially arbitrary code execution. The vulnerabilities affect the Debian stable (Trixie) distribution and are addressed through an updated apr-util package.
• CVE-2025-49506 – A security vulnerability in apr-util that could contribute to denial of service or arbitrary code execution.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Apache Portable Runtime Utility (apr-util), which could result in denial of service or potentially arbitrary code execution. The vulnerabilities affect the Debian stable (Trixie) distribution and are addressed through an updated apr-util package.
• CVE-2025-49506 – A security vulnerability in apr-util that could contribute to denial of service or arbitrary code execution.[emaillocker id="1283"]
• CVE-2026-32327 – A security vulnerability in apr-util that could result in denial of service or potentially arbitrary code execution.
• CVE-2026-34501 – A security vulnerability affecting apr-util that could lead to denial of service or potentially arbitrary code execution.
• CVE-2026-34502 – A security vulnerability affecting apr-util that could lead to denial of service or potentially arbitrary code execution.
We recommend you to update apr-util to version 1.6.3-3+deb13u1.
The following reports contain further technical details:
[/emaillocker]