[CLSA-2026:1786633537] Fix CVE(s): CVE-2024-23672, CVE-2024-56337
Type:
security
Severity:
Important
Release date:
2026-08-13 15:05:47 UTC
Description:
* SECURITY UPDATE: DoS via incomplete cleanup vulnerability - debian/patches/CVE-2024-23672.patch: add a session close timeout so a client that never answers the close message cannot hold the connection open, in java/org/apache/tomcat/websocket/WsSession.java - CVE-2024-23672 * SECURITY UPDATE: TOCTOU race condition on case insensitive file systems - debian/patches/CVE-2024-56337.patch: disable the JVM canonical file name cache via sun.io.useCanonCaches in bin/catalina.sh - CVE-2024-56337
Updated packages:
  • libservlet3.1-java_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:53b1f6f83a4dbf9e273c3799dea22fdbaf859715
  • libservlet3.1-java-doc_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:7b78f3d8e715f7094bfaba122f8ca11b69f46db4
  • libtomcat8-java_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:66c9e9beb92e7751e9941a6aacce45179cd91f8f
  • tomcat8_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:f16c0666f00bbf8b0b8e9fe0f30e05af4daec6bf
  • tomcat8-admin_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:e9951ce8918bab8ea0c1e66d01af7a2aecd9a942
  • tomcat8-common_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:63337b822476184686a460d79d80108a14245bb3
  • tomcat8-docs_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:d7dc37d413b9e6371c55114fb1a71d392d3fa727
  • tomcat8-examples_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:5ece95a287fca1f97dfab07b1115c3e03de9c985
  • tomcat8-user_8.0.32-1ubuntu1.13+tuxcare.els5_all.deb
    sha:219c279e76af4343eaf29b8106876f3818682994
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.