CVE-2026-34501

EUVD-2026-53917
Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client.

This issue affects Apache Portable Runtime Utility: from 1.6.0 through 1.6.3.

Users are recommended to upgrade to version 1.6.4, which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
apacheCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 42.39%
Affected Products (NVD)
VendorProductVersion
apacheapr-util
1.6.0 ≤
𝑥
< 1.6.4
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
apacheportable_runtime_utility
1.6.0 ≤
𝑥
≤ 1.6.3
CNA
Debian logo
Debian Releases
Debian Product
Codename
apr-util
bookworm
vulnerable
bookworm (security)
1.6.3-1+deb12u1
fixed
forky
1.6.4-2
fixed
sid
1.6.4-2
fixed
trixie
1.6.3-3+deb13u1
fixed
trixie (security)
1.6.3-3+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apr-util
bionic
Fixed 1.6.1-2ubuntu0.1+esm1
released
focal
Fixed 1.6.1-4ubuntu2.2+esm1
released
jammy
Fixed 1.6.1-5ubuntu4.22.04.3
released
noble
Fixed 1.6.3-1.1ubuntu7.1
released
resolute
Fixed 1.6.3-3ubuntu3.1
released
trusty
Fixed 1.5.3-1ubuntu0.1~esm3
released
xenial
Fixed 1.5.4-1ubuntu0.1~esm1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
apr-util-devel
suse enterprise desktop 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP7
1.6.1-150600.27.3.1
fixed
libapr-util1
suse enterprise desktop 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP7
1.6.1-150600.27.3.1
fixed
libapr-util1-dbd-mysql
suse enterprise sap 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP7
1.6.1-150600.27.3.1
fixed
libapr-util1-dbd-pgsql
suse enterprise sap 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP7
1.6.1-150600.27.3.1
fixed
libapr-util1-dbd-sqlite3
suse enterprise sap 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise sap 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise sap 15 SP7
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP4
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP5
1.6.1-150300.18.8.1
fixed
suse enterprise server 15 SP6
1.6.1-150600.27.3.1
fixed
suse enterprise server 15 SP7
1.6.1-150600.27.3.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
apr-util
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-bdb
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-devel
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-ldap
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-mysql
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-odbc
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-openssl
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-pgsql
RHEL 9
0:1.6.1-23.el9_8.1
fixed
apr-util-sqlite
RHEL 9
0:1.6.1-23.el9_8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
apr-util
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-bdb
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
apr-util-debuginfo
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-debugsource
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-devel
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-ldap
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-ldap-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-lmdb
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-lmdb-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-mysql
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-mysql-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-nss
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
apr-util-odbc
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-odbc-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-openssl
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-openssl-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-pgsql
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-pgsql-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-sqlite
Amazon Linux 2
0:1.6.5-1.amzn2.0.1
fixed
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
apr-util-sqlite-debuginfo
Amazon Linux 2023
0:1.6.5-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
apr-util
Azure Linux 3.0
0:1.6.3-3.azl3
fixed