Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:23739 - Security Advisory
Issued:
2025-12-22
Updated:
2025-12-22

RHSA-2025:23739 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: mod_md security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for mod_md is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

This module manages common properties of domains for one or more virtual hosts. Specifically it can use the ACME protocol to automate certificate provisioning. Certificates will be configured for managed domains and their virtual hosts automatically, including at renewal.

Security Fix(es):

  • mod_md: Apache HTTP Server: mod_md (ACME), unintended retry intervals (CVE-2025-55753)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64

Fixes

  • BZ - 2419140 - CVE-2025-55753 mod_md: Apache HTTP Server: mod_md (ACME), unintended retry intervals

CVEs

  • CVE-2025-55753

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
mod_md-2.4.26-1.el9_7.1.src.rpm SHA-256: 25a0fd8597b8263ad2222384f045a043a02c16e162f090d49236bbf58a4bee54
x86_64
mod_md-2.4.26-1.el9_7.1.x86_64.rpm SHA-256: 57130eab71229294f08f28b0f2ac2d4200e81e8f49a97dca2bcdac4736a26ab7
mod_md-debuginfo-2.4.26-1.el9_7.1.x86_64.rpm SHA-256: aff9aa7b744420ad946c34867f520e5f70fac53a97bdb4a20ac075900f20f3b1
mod_md-debugsource-2.4.26-1.el9_7.1.x86_64.rpm SHA-256: 27e22ea37643b43419f82cfd50bae4c492063920daea16cb4ad5a265ed2a9ca1

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
mod_md-2.4.26-1.el9_7.1.src.rpm SHA-256: 25a0fd8597b8263ad2222384f045a043a02c16e162f090d49236bbf58a4bee54
s390x
mod_md-2.4.26-1.el9_7.1.s390x.rpm SHA-256: 3561068f1b02ad5fbd574d79f75663ad1301ac259314d96ba251953290b82321
mod_md-debuginfo-2.4.26-1.el9_7.1.s390x.rpm SHA-256: 13bf6bcb7e42ded927d1b6c9134ac115d3a9f2773663a0feb628d1087b9763e2
mod_md-debugsource-2.4.26-1.el9_7.1.s390x.rpm SHA-256: c939daa3d1a4400c9df2cc4f72f9eef5f6365c12f0b145360ee0298f79801bca

Red Hat Enterprise Linux for Power, little endian 9

SRPM
mod_md-2.4.26-1.el9_7.1.src.rpm SHA-256: 25a0fd8597b8263ad2222384f045a043a02c16e162f090d49236bbf58a4bee54
ppc64le
mod_md-2.4.26-1.el9_7.1.ppc64le.rpm SHA-256: 317115177407ec28d935c0ef8a31ed90786b7b47ac79bd8c196c8713bb6bb323
mod_md-debuginfo-2.4.26-1.el9_7.1.ppc64le.rpm SHA-256: 76e4ea3a9ac3b9d589dc3566aa3878cc98c327a7cb6ecdde7abc6f8958040038
mod_md-debugsource-2.4.26-1.el9_7.1.ppc64le.rpm SHA-256: 11fa2231cb7943e497251e07e0c15d2b49bc397eb555afed4e5da91d2fa10ee3

Red Hat Enterprise Linux for ARM 64 9

SRPM
mod_md-2.4.26-1.el9_7.1.src.rpm SHA-256: 25a0fd8597b8263ad2222384f045a043a02c16e162f090d49236bbf58a4bee54
aarch64
mod_md-2.4.26-1.el9_7.1.aarch64.rpm SHA-256: cdd81daf43273ad7399651b611955a10e3998f84793a201607665ce2578b53f7
mod_md-debuginfo-2.4.26-1.el9_7.1.aarch64.rpm SHA-256: cf57f7f9809a6e3bde0c767fac4056f64799be1471c0887032f82b3478dd7bae
mod_md-debugsource-2.4.26-1.el9_7.1.aarch64.rpm SHA-256: 6bc104c9a71306c050b0a631265da6d730a7cffca955464b5c1ed72e777dc6f3

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility