关键漏洞信息 漏洞概述 公告编号: RHSA-2025:10007 类型/严重性: 安全公告 - 重要 主题: mod_auth_openidc 的安全更新,适用于 Red Hat Enterprise Linux 9.4 Extended Update Support。 漏洞描述 模块: mod_auth_openidc 是 Apache HTTP Server 的 OpenID Connect 认证模块。 安全修复: - DoS via Empty POST in mod_auth_openidc with OIDCPreservePost Enabled (CVE-2025-3891) 影响的产品 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.4 x86_64 Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.4 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.4 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.4 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x 解决方案 参考文档: https://access.redhat.com/articles/11256 CVE 编号 CVE-2025-3891 参考链接 https://access.redhat.com/security/updates/classification/#important