|
|
Log in / Subscribe / Register

Ubuntu alert USN-8450-1 (tomcat11)

From:  noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com>
To:  ubuntu-security-announce@lists.ubuntu.com
Subject:  [USN-8450-1] Tomcat vulnerabilities
Date:  Thu, 18 Jun 2026 17:39:41 +0000
Message-ID:  <E1waGiL-0001FB-Nr@lists.ubuntu.com>
Cc:  noreply+usn-bot@canonical.com

========================================================================== Ubuntu Security Notice USN-8450-1 June 18, 2026 tomcat11 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat11: Servlet and JSP engine Details: It was discovered that Tomcat did not properly limit the size of WebDAV LOCK and PROPFIND request bodies. A remote attacker could possibly use this issue to cause Tomcat to consume excessive memory, resulting in a denial of service. (CVE-2026-41284) It was discovered that Tomcat incorrectly validated HTTP/2 header fields. A remote attacker could use this issue to cause Tomcat to crash or possibly execute arbitrary code. (CVE-2026-41293) It was discovered that Tomcat did not properly clear HTTP authentication headers during WebSocket connection upgrades and redirects. A remote attacker could possibly use this issue to obtain sensitive credentials. (CVE-2026-42498) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtomcat11-embed-java 11.0.18-1ubuntu0.1~esm1 Available with Ubuntu Pro libtomcat11-java 11.0.18-1ubuntu0.1~esm1 Available with Ubuntu Pro tomcat11 11.0.18-1ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8450-1 CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43515


Attachment: signature.asc (type=application/pgp-signature)

-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmo0LFgACgkQcpJm3tlz hgHqvhAAuNPn0dnBk8L1Eu76ynzM7FXOreskMf+ZV7eRdlTNcnHH1320eryO+zK/ zQQ2FY9PMhfMg5E3rU57fo9xK7Ln0dEMNoMwocVvuhV0P+0zef0fXvd0h5/VnP7C gAkYbP0IQd4qB4YDEczYWUPPX/AjBaZcU4FDmK/3b1SdJ2BlKDHPGzoh67dv0l4u ClbKgRC8NCRAM65xW6i+UDumjRzd4sJwaal30n0ZEsaxDjMTCvA4CBmksrRUDbdm vpeRqDSg0kSnbs0u7EKgsqg1Nx44kHgu8qNI+EbI3ss0UJVtA/AGaqsTkxn8w4eW LvmB6RaT11JExCSBaN+Adus2Cwff0hpQlVMt4o5B4rekUAhLleU3CHrmlpGJa0TN bQAvZk+M3Ut5SSqJ7aqKcvnaQUYN+S5HqhsOmoOQrjSDW2ONxCeOkKeLTHH3klsn KiWmTgSnAPYsB8GO1g4sBARBaZ3EGnMBUeKr8PFoqQqMb0yCLH4TYzcl3Csgyu3s bvGaJ/newlXZBRmhSDSHLzJSYF/lhfL/Tewc3BPC03IZXbTHPtVIY/nZgTfzln8l cBwp8+En2ASjzZK3OpasPi8fHmZV0GuE3abuXYCvVxRbJv3CG2+6V/YKrF1NZFH3 L8mkvUr8mHAiycjJ/hb2C4GaFuWwa+WU52X/lzOFJkKgXgXSKlw= =cYz5 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds