Release date:
2026-08-13 15:05:47 UTC
Description:
* SECURITY UPDATE: DoS via incomplete cleanup vulnerability
- debian/patches/CVE-2024-23672.patch: add a session close timeout so a
client that never answers the close message cannot hold the connection
open, in java/org/apache/tomcat/websocket/WsSession.java
- CVE-2024-23672
* SECURITY UPDATE: TOCTOU race condition on case insensitive file systems
- debian/patches/CVE-2024-56337.patch: disable the JVM canonical file name
cache via sun.io.useCanonCaches in bin/catalina.sh
- CVE-2024-56337
Updated packages:
-
libservlet3.1-java_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:53b1f6f83a4dbf9e273c3799dea22fdbaf859715
-
libservlet3.1-java-doc_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:7b78f3d8e715f7094bfaba122f8ca11b69f46db4
-
libtomcat8-java_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:66c9e9beb92e7751e9941a6aacce45179cd91f8f
-
tomcat8_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:f16c0666f00bbf8b0b8e9fe0f30e05af4daec6bf
-
tomcat8-admin_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:e9951ce8918bab8ea0c1e66d01af7a2aecd9a942
-
tomcat8-common_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:63337b822476184686a460d79d80108a14245bb3
-
tomcat8-docs_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:d7dc37d413b9e6371c55114fb1a71d392d3fa727
-
tomcat8-examples_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:5ece95a287fca1f97dfab07b1115c3e03de9c985
-
tomcat8-user_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
sha:219c279e76af4343eaf29b8106876f3818682994
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.