Ubuntu alert USN-8417-1 (tomcat9, tomcat10)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8417-1] Tomcat vulnerabilities | |
| Date: | Wed, 10 Jun 2026 10:23:18 +0000 | |
| Message-ID: | <E1wXG5e-0005wl-Kj@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8417-1 June 10, 2026 tomcat9, tomcat10 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat10: Servlet and JSP engine - tomcat9: Servlet and JSP engine Details: It was discovered that Tomcat did not properly limit the size of WebDAV LOCK and PROPFIND request bodies. A remote attacker could use this issue to cause Tomcat to consume excessive memory, resulting in a denial of service. (CVE-2026-41284) It was discovered that Tomcat incorrectly validated HTTP/2 header fields. A remote attacker could use this issue to cause Tomcat to crash or possibly execute arbitrary code. (CVE-2026-41293) It was discovered that Tomcat did not properly clear HTTP authentication headers during WebSocket connection upgrades and redirects. A remote attacker could use this issue to obtain sensitive credentials. (CVE-2026-42498) It was discovered that Tomcat incorrectly handled digest authentication. A remote attacker could possibly use this issue to bypass authentication restrictions. (CVE-2026-43512) It was discovered that Tomcat incorrectly handled case sensitivity in LockOutRealm. A remote attacker could possibly use this issue to bypass account lockout protections and obtain sensitive information. (CVE-2026-43513) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtomcat10-embed-java 10.1.40-1ubuntu1.26.04.1 libtomcat10-java 10.1.40-1ubuntu1.26.04.1 libtomcat9-java 9.0.115-1ubuntu0.1 tomcat10 10.1.40-1ubuntu1.26.04.1 Ubuntu 25.10 libtomcat10-embed-java 10.1.40-1ubuntu1.25.10.1 libtomcat10-java 10.1.40-1ubuntu1.25.10.1 libtomcat9-java 9.0.95-1ubuntu1.1 tomcat10 10.1.40-1ubuntu1.25.10.1 Ubuntu 24.04 LTS libtomcat10-embed-java 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro libtomcat10-java 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro libtomcat9-java 9.0.70-2ubuntu0.1+esm3 Available with Ubuntu Pro tomcat10 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 22.04 LTS libtomcat9-embed-java 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro libtomcat9-java 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro tomcat9 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro Ubuntu 20.04 LTS libtomcat9-embed-java 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro libtomcat9-java 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro tomcat9 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libtomcat9-embed-java 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro libtomcat9-java 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro tomcat9 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro After a standard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8417-1 CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43512, CVE-2026-43513, CVE-2026-43515 Package Information: https://launchpad.net/ubuntu/+source/tomcat10/10.1.40-1ub... https://launchpad.net/ubuntu/+source/tomcat9/9.0.115-1ubu... https://launchpad.net/ubuntu/+source/tomcat10/10.1.40-1ub... https://launchpad.net/ubuntu/+source/tomcat9/9.0.95-1ubun...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmopLDoACgkQcpJm3tlz hgEIuBAArnDckdA4EDsxeseoBKuPbQmTmUTVuILLbRy5JN6n2epcQEOZhKqnBSPl JWWYgwSyGdg19sNnbMmA96n4cb1hHRRXHPJayIJxrl/QTvO5fr83XgzQav6CdV1b Ola21QSpJI/EXxydCvwMftP/YAGJVnZQDbCCNdhismgm3nuCorSy1aLcCGaS+Zpp FWfrbgcoz3ZmjPborHCQ55hhufx488CItpPbG7R0Lte2o768xGBf+xPIqqwREoKT uo+5ULHeun6+QYAnGsdR/TuPueiQxc9q0rqAtqsr+qafUDUWA/OMjvJbSUImZnay 2RqTRznSMpKEb3qhpkUDszd51+S5eQqG0JFparOF1wdUA4e7CWMhfmSS3Bf5epbI ZnORpNqYnqLWIlHNBnoc7s+U8IxS1NO6qTy0Bk2eRV9ABZfihnPUkdZzf2cYgZfk xMwKJ3fhszYZSEfRQP0AGawVm+2dqxv66/Cd+0f5S3U11SV+kgU+wQHnO8L9GHpE KX+rCvNbDEJzqJT4v3J/Os74wQLr0p9qv+saibNQz1HDwSZtKWw1A2kMd8DoI7Fs Bvpf0rz+Ir3Al/Tb26QWCgD7t22QHWNjmJExsEgKGv5+oR14shn4IhQ7Q/mutAKo nZx9lNr3rzRSL54lfzI7Dx6QGigJ4bbaC8+aVJ1ZHloOybywGoE= =3gmN -----END PGP SIGNATURE-----
