[CLSA-2026:1785309072] Fix CVE(s): CVE-2026-55957
Type:
security
Severity:
Important
Release date:
2026-07-29 07:11:23 UTC
Description:
* SECURITY UPDATE: JNDIRealm bypass when configured with GSSAPI authentication - HttpServletRequest.login(username, password) calls validated credentials via the GSSAPI SASL mechanism instead of a plain LDAP bind, silently accepting arbitrary passwords - debian/patches/CVE-2026-55957.patch: preserve DirContext environment, drop the GSSAPI SECURITY_AUTHENTICATION setting before the user-credential bind, and restore it in a finally block via the existing restoreEnvironmentParameter() helper - CVE-2026-55957
CVEs fixed:
Updated packages:
  • libtomcat9-embed-java_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:19870540dcb7017a6134157c1d62b98a78e36831
  • libtomcat9-java_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:9f39ab437711be2698edc461c382d5ddb6cf7895
  • tomcat9_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:02478f7eac2362c7014545a8226e432c5d150ba5
  • tomcat9-admin_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:e2531a9cd240cf6cc0c3b2eff412dd6c4e7a59e5
  • tomcat9-common_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:e7adef00c248c77001451604b6a71a764b9b21e6
  • tomcat9-docs_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:225170ae8bd07716a3a3779008df06ba3eabe9d0
  • tomcat9-examples_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:3538efcb6b33444cfea32eda32cfbce6841c51ab
  • tomcat9-user_9.0.31-1~deb10u12+tuxcare.els6_all.deb
    sha:d07acd5afa5fc7d5a0f4d15ea78dd5a660dc1068
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.