Release date:
2026-07-29 07:11:23 UTC
Description:
* SECURITY UPDATE: JNDIRealm bypass when configured with GSSAPI
authentication - HttpServletRequest.login(username, password) calls
validated credentials via the GSSAPI SASL mechanism instead of a
plain LDAP bind, silently accepting arbitrary passwords
- debian/patches/CVE-2026-55957.patch: preserve DirContext
environment, drop the GSSAPI SECURITY_AUTHENTICATION setting
before the user-credential bind, and restore it in a finally
block via the existing restoreEnvironmentParameter() helper
- CVE-2026-55957
Updated packages:
-
libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:19870540dcb7017a6134157c1d62b98a78e36831
-
libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:9f39ab437711be2698edc461c382d5ddb6cf7895
-
tomcat9_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:02478f7eac2362c7014545a8226e432c5d150ba5
-
tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:e2531a9cd240cf6cc0c3b2eff412dd6c4e7a59e5
-
tomcat9-common_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:e7adef00c248c77001451604b6a71a764b9b21e6
-
tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:225170ae8bd07716a3a3779008df06ba3eabe9d0
-
tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:3538efcb6b33444cfea32eda32cfbce6841c51ab
-
tomcat9-user_9.0.31-1~deb10u12+tuxcare.els6_all.deb
sha:d07acd5afa5fc7d5a0f4d15ea78dd5a660dc1068
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.