Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Insights
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Insights
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8922 - Security Advisory
Issued:
2025-06-11
Updated:
2025-06-11

RHSA-2025:8922 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: mod_security security update

Type/Severity

Security Advisory: Important

Red Hat Insights patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for mod_security is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

ModSecurity is an open source intrusion detection and prevention engine for web applications.

Security Fix(es):

  • modsecurity: ModSecurity Has Possible DoS Vulnerability (CVE-2025-47947)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2367903 - CVE-2025-47947 modsecurity: ModSecurity Has Possible DoS Vulnerability

CVEs

  • CVE-2025-47947

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
mod_security-2.9.3-12.el9_0.1.src.rpm SHA-256: 2e9fa0b4edc07bb9ca01f60ca62f912b2cf3e468de7abea50cebc8822eeef5db
ppc64le
mod_security-2.9.3-12.el9_0.1.ppc64le.rpm SHA-256: 05d3837b395d26ba229b0902f53846f37920ca04865facc50fd049c963d6f9aa
mod_security-debuginfo-2.9.3-12.el9_0.1.ppc64le.rpm SHA-256: 29759a2e8fe798f38d220abf4e08bfd4832b0e7c26a325a69c3a7bee0822700a
mod_security-debugsource-2.9.3-12.el9_0.1.ppc64le.rpm SHA-256: 5ebd336f2708b5788bc9db6e4803c00f728979bcd789091708bcd62a2a674bf8
mod_security-mlogc-2.9.3-12.el9_0.1.ppc64le.rpm SHA-256: c85a89a1707c869fc6ca4f1b68c7b0922cc735e7bb50de91add99de88d4c9635
mod_security-mlogc-debuginfo-2.9.3-12.el9_0.1.ppc64le.rpm SHA-256: 3864170a279d0d1891020f0388559e1c38d0442b37aa629f39a33677248fa55c

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
mod_security-2.9.3-12.el9_0.1.src.rpm SHA-256: 2e9fa0b4edc07bb9ca01f60ca62f912b2cf3e468de7abea50cebc8822eeef5db
x86_64
mod_security-2.9.3-12.el9_0.1.x86_64.rpm SHA-256: 7a3432d747e23e043c996687c74775c5648623017c889793439736e4dbd08234
mod_security-debuginfo-2.9.3-12.el9_0.1.x86_64.rpm SHA-256: 83a1bcd60f893ed604f33700379fa262f9fd745d319a64372ee3b370da07144c
mod_security-debugsource-2.9.3-12.el9_0.1.x86_64.rpm SHA-256: 89927eaae46e18464c1d735850d84851a7ccbec6ac9f0ba9ec7f6831f57e66be
mod_security-mlogc-2.9.3-12.el9_0.1.x86_64.rpm SHA-256: 571cddd8a832d6df8aeabf60057b630670deecad9abdd3fc213c4ccd6a57c3b4
mod_security-mlogc-debuginfo-2.9.3-12.el9_0.1.x86_64.rpm SHA-256: 315543259bc9e540dd63c786355f97e26151ac8047702917dae801035fac2748

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
mod_security-2.9.3-12.el9_0.1.src.rpm SHA-256: 2e9fa0b4edc07bb9ca01f60ca62f912b2cf3e468de7abea50cebc8822eeef5db
aarch64
mod_security-2.9.3-12.el9_0.1.aarch64.rpm SHA-256: a72f949b91c4b73b9b274b6174d8223b26c59e321994f45d34613e5631a66da8
mod_security-debuginfo-2.9.3-12.el9_0.1.aarch64.rpm SHA-256: da780dce738a095b3f18e4ce97519be3094d4344e24e492690e3db819ffb6047
mod_security-debugsource-2.9.3-12.el9_0.1.aarch64.rpm SHA-256: e39ee0598a9e5073f137e41ca8e61c7b3b8a8b3c343f61e630aee00d52fcae0e
mod_security-mlogc-2.9.3-12.el9_0.1.aarch64.rpm SHA-256: 0dbaa72f0ee01507dabd09185a84cc66d6c70cdefba13cbd80d7887a310524b2
mod_security-mlogc-debuginfo-2.9.3-12.el9_0.1.aarch64.rpm SHA-256: d1e9b7404c9d5be59b617d751e9c5e84c50e9cf781dfbb6d1aa13df70d467609

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
mod_security-2.9.3-12.el9_0.1.src.rpm SHA-256: 2e9fa0b4edc07bb9ca01f60ca62f912b2cf3e468de7abea50cebc8822eeef5db
s390x
mod_security-2.9.3-12.el9_0.1.s390x.rpm SHA-256: 817c2793e9bab9133e126a588f421466d43b822fd6b45d86b460538459168072
mod_security-debuginfo-2.9.3-12.el9_0.1.s390x.rpm SHA-256: 6ebc3172344bf5c51ce6e63a7374b5672eef2ce5b759399ab545ad5a4cf9212b
mod_security-debugsource-2.9.3-12.el9_0.1.s390x.rpm SHA-256: d420212c74fd06054ee4d72c390fa79c8027b9ba3773c228f447ee00a8d1842b
mod_security-mlogc-2.9.3-12.el9_0.1.s390x.rpm SHA-256: 5f6114abdbffc23388cb56182b461ddd1a624707a8d935c027541370e1a880d3
mod_security-mlogc-debuginfo-2.9.3-12.el9_0.1.s390x.rpm SHA-256: fc4488d7e88cccf2dd9b340e8d2d1213bae9431f06ea684824684f1c91963304

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility