Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:13670 - Security Advisory
Issued:
2025-08-12
Updated:
2025-08-12

RHSA-2025:13670 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: mod_security security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for mod_security is now available for Red Hat Enterprise Linux 9.4 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

ModSecurity is an open source intrusion detection and prevention engine for web applications.

Security Fix(es):

  • mod_security: ModSecurity Denial of Service Vulnerability (CVE-2025-48866)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64
  • Red Hat Enterprise Linux Server - AUS 9.4 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x

Fixes

  • BZ - 2369827 - CVE-2025-48866 mod_security: ModSecurity Denial of Service Vulnerability

CVEs

  • CVE-2025-48866

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
x86_64
mod_security-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: e9f6bbd66077f702b9fd7cc58ef599269399f17ee3f94a37025e66374c2eeb07
mod_security-debuginfo-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 3250475129d8e3176776636e5f0637404df32a080f53323f678e38d3fa501afe
mod_security-debugsource-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 13109e2b1bd837afc8c64a497c295a2314c5233fb0186e769a902264660f3817
mod_security-mlogc-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 84d6008677d0ef6a73f603c65971086991233e53af06fdebed2e5b202e47f30c
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 16db4c056d3dbe3a5fe26687c04e8a5454148ad07737ebb1bc2accd85f763695

Red Hat Enterprise Linux Server - AUS 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
x86_64
mod_security-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: e9f6bbd66077f702b9fd7cc58ef599269399f17ee3f94a37025e66374c2eeb07
mod_security-debuginfo-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 3250475129d8e3176776636e5f0637404df32a080f53323f678e38d3fa501afe
mod_security-debugsource-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 13109e2b1bd837afc8c64a497c295a2314c5233fb0186e769a902264660f3817
mod_security-mlogc-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 84d6008677d0ef6a73f603c65971086991233e53af06fdebed2e5b202e47f30c
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 16db4c056d3dbe3a5fe26687c04e8a5454148ad07737ebb1bc2accd85f763695

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
s390x
mod_security-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 51969f260becdb4c63e71d5ef299c84fb06f0746ae5b7513a883ef6c1934a830
mod_security-debuginfo-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 9593ddc2fd7cb98b53d756ea2ccd5f2e89ce9e526cbf918cf10deef24e2fb6ae
mod_security-debugsource-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 262b4e3164786d11073e973fe00c1c5838bfc4b0542ff86cdfa63aa4fbf455df
mod_security-mlogc-2.9.6-1.el9_4.2.s390x.rpm SHA-256: a794fd055fde215a5335824c38ff05b46b7c90de08ed47e441bc26ab6d9c7170
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 74527cd0d54d25ffcff26953c9df4a4933d17ef28df8ebc41b4012057709c359

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
ppc64le
mod_security-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: 8524b9eaabc0da3d06a59c2c3fbe511c86dc5508d15078886889efc128a00bca
mod_security-debuginfo-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: 54ee3bafab059c2ae2ccd7d9a68e6c79e240c141ed3bc34d285cd597c217ce01
mod_security-debugsource-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: af84117cf84639f420cd2dec7eead2fcc3743e84ee595a52c76ba085b512b84d
mod_security-mlogc-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: 870d31a9e6d345ed569202f08c0aca3cbbe97327278c6c0d0ea5fc31f0d0c8fd
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: e8e98ef84b04cd58ac59360fa7a095409e994292043ff5b85da3a8fbcd3d4d8c

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
aarch64
mod_security-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 68c7510e94f2f32f768fc624b466ef8d8be5f66217d9f5db5522f183115bbb3d
mod_security-debuginfo-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 58eb5f735ae732b42b17a02254776ccd7c75cb380c84a8accbafd901fe60d031
mod_security-debugsource-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: dc08208c11aa2431d191549d21e5da902d7ac9090980ce2f6cbfa220334673ed
mod_security-mlogc-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 1bf2a88466a66760051075345ae61a2365245c49181210e453c4b3f4849132e3
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 2e4046645bb86755f9c893f20678f63e05e0c75b75e6f1b836ee786a423d76f5

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
ppc64le
mod_security-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: 8524b9eaabc0da3d06a59c2c3fbe511c86dc5508d15078886889efc128a00bca
mod_security-debuginfo-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: 54ee3bafab059c2ae2ccd7d9a68e6c79e240c141ed3bc34d285cd597c217ce01
mod_security-debugsource-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: af84117cf84639f420cd2dec7eead2fcc3743e84ee595a52c76ba085b512b84d
mod_security-mlogc-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: 870d31a9e6d345ed569202f08c0aca3cbbe97327278c6c0d0ea5fc31f0d0c8fd
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.ppc64le.rpm SHA-256: e8e98ef84b04cd58ac59360fa7a095409e994292043ff5b85da3a8fbcd3d4d8c

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
x86_64
mod_security-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: e9f6bbd66077f702b9fd7cc58ef599269399f17ee3f94a37025e66374c2eeb07
mod_security-debuginfo-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 3250475129d8e3176776636e5f0637404df32a080f53323f678e38d3fa501afe
mod_security-debugsource-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 13109e2b1bd837afc8c64a497c295a2314c5233fb0186e769a902264660f3817
mod_security-mlogc-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 84d6008677d0ef6a73f603c65971086991233e53af06fdebed2e5b202e47f30c
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.x86_64.rpm SHA-256: 16db4c056d3dbe3a5fe26687c04e8a5454148ad07737ebb1bc2accd85f763695

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
aarch64
mod_security-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 68c7510e94f2f32f768fc624b466ef8d8be5f66217d9f5db5522f183115bbb3d
mod_security-debuginfo-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 58eb5f735ae732b42b17a02254776ccd7c75cb380c84a8accbafd901fe60d031
mod_security-debugsource-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: dc08208c11aa2431d191549d21e5da902d7ac9090980ce2f6cbfa220334673ed
mod_security-mlogc-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 1bf2a88466a66760051075345ae61a2365245c49181210e453c4b3f4849132e3
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.aarch64.rpm SHA-256: 2e4046645bb86755f9c893f20678f63e05e0c75b75e6f1b836ee786a423d76f5

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4

SRPM
mod_security-2.9.6-1.el9_4.2.src.rpm SHA-256: ab95f443852e88e64bca2fb2879228ae627b746dc427fd5f2f261ed042c785e9
s390x
mod_security-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 51969f260becdb4c63e71d5ef299c84fb06f0746ae5b7513a883ef6c1934a830
mod_security-debuginfo-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 9593ddc2fd7cb98b53d756ea2ccd5f2e89ce9e526cbf918cf10deef24e2fb6ae
mod_security-debugsource-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 262b4e3164786d11073e973fe00c1c5838bfc4b0542ff86cdfa63aa4fbf455df
mod_security-mlogc-2.9.6-1.el9_4.2.s390x.rpm SHA-256: a794fd055fde215a5335824c38ff05b46b7c90de08ed47e441bc26ab6d9c7170
mod_security-mlogc-debuginfo-2.9.6-1.el9_4.2.s390x.rpm SHA-256: 74527cd0d54d25ffcff26953c9df4a4933d17ef28df8ebc41b4012057709c359

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility