Debian has issued an advisory on June 8: https://lists.debian.org/debian-security-announce/2025/msg00104.html Fixes: https://github.com/owasp-modsecurity/ModSecurity/commit/fdfc2d5b21610651b0cefceb397be2cfc7aac8bb (CVE-2025-47947) https://github.com/owasp-modsecurity/ModSecurity/commit/3a54ccea62d3f7151bb08cb78d60c5e90b53ca2e (CVE-2025-48866)
Whiteboard: (none) => MGA9TOOSource RPM: (none) => apache-mod_security-2.9.7-2.mga10.src.rpm, apache-mod_security-2.9.7-1.mga9.src.rpmStatus comment: (none) => Fixed upstream in 2.9.10 and patches available from upstream and DebianCVE: (none) => CVE-2025-47947, CVE-2025-48866
Thanks for the patch refs. Assigning globally, no one packager evident.
Assignee: bugsquad => pkg-bugs
Ubuntu has issued an advisory on June 16: https://ubuntu.com/security/notices/USN-7567-1
Suggested advisory: ======================== The updated packages fix security vulnerabilities: ModSecurity Has Possible DoS Vulnerability. (CVE-2025-47947) ModSecurity has possible DoS vulnerability in sanitiseArg action. (CVE-2025-48866) References: https://lists.debian.org/debian-security-announce/2025/msg00104.html https://ubuntu.com/security/notices/USN-7567-1 ======================== Updated packages in core/updates_testing: ======================== apache-mod_security-2.9.7-1.1.mga9 mlogc-2.9.7-1.1.mga9 from SRPM: apache-mod_security-2.9.7-1.1.mga9.src.rpm
Status: NEW => ASSIGNEDWhiteboard: MGA9TOO => (none)Version: Cauldron => 9Source RPM: apache-mod_security-2.9.7-2.mga10.src.rpm, apache-mod_security-2.9.7-1.mga9.src.rpm => apache-mod_security-2.9.7-1.mga9.src.rpmAssignee: pkg-bugs => qa-bugsStatus comment: Fixed upstream in 2.9.10 and patches available from upstream and Debian => (none)
Keywords: (none) => advisory
MGA9-64 server Plasma Wayland on Compaq H000SB No installation issues. Ref bug 31457 for test # httpd -M 2>/dev/null |grep security security2_module (shared) Test is OK, good to go.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA9-64-OK
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0192.html
Status: ASSIGNED => RESOLVEDResolution: (none) => FIXED