[CLSA-2026:1786720463] Fix CVE(s): CVE-2024-56337
Type:
security
Severity:
Important
Release date:
2026-08-14 15:14:34 UTC
Description:
* SECURITY UPDATE: fix for the following CVEs: - CVE-2024-56337: incomplete mitigation of CVE-2024-50379 — the JVM global canonical file name cache (sun.io.useCanonCaches) could still return a stale answer for a concurrently written path, leaving the TOCTOU race during JSP compilation exploitable on case-insensitive file systems with a write-enabled Default Servlet. DirResourceSet now verifies at startup that the cache is disabled, disabling it reflectively where possible and refusing to start the potentially vulnerable web application otherwise; new Jre12Compat and Jre21Compat tiers implement the per-JRE detection, and catalina.sh sets -Dsun.io.useCanonCaches=false before the JVM caches it.
CVEs fixed:
Updated packages:
  • libtomcat9-embed-java_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:5262df04f0b9a280abeea1192aa7b32ca405b776
  • libtomcat9-java_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:b8681a0527344814c10a12d2f61c17d513f5936e
  • tomcat9_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:bddb71b3f30c93d0605da5e140c3b72c060c4ac0
  • tomcat9-admin_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:4f40affda531081b72bd1a422b2b4660778ba740
  • tomcat9-common_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:a29da9ca19e30eb09f34de1a871dabd062253b22
  • tomcat9-docs_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:c689f5e7201c8aaf8c12808fa80da597fb222c08
  • tomcat9-examples_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:dc98ba9888593b99581a38e2c7ecb7488208af0c
  • tomcat9-user_9.0.31-1ubuntu0.9+tuxcare.els8_all.deb
    sha:bde096c16d3d4de0d27dc1ffca66aa7ce733cec2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.