Release date:
2026-07-20 09:55:41 UTC
Description:
* SECURITY UPDATE: JNDIRealm credential validation bypass when
configured to use GSSAPI
- debian/patches/CVE-2026-55957.patch: in bindAsUser preserve the
current SASL environment, move userCredentialsAdd inside the try,
strip Context.SECURITY_AUTHENTICATION="GSSAPI" before the LDAP bind
so the provided username/password are actually validated, and
restore the original SASL setting in a finally block along with
userCredentialsRemove. Also updates docs/config/realm.xml to
document that GSSAPI is skipped for calls made via
HttpServletRequest.login(String, String).
- CVE-2026-55957
Updated packages:
-
libtomcat9-embed-java_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:0737236b64bc9ebddc3bf2552fe76ef6d1a43cd7
-
libtomcat9-java_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:38f23df4d336490568460c361627a807ebc7cb19
-
tomcat9_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:748336b6a6db61e2bc1b62a9b69228faf6946d61
-
tomcat9-admin_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:9d37e27bcadbce1550c46ee8e3c4093b654056b2
-
tomcat9-common_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:8b92a4f423bbc72593f0f567a2d60b5b94a42ebf
-
tomcat9-docs_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:575d49e9fc6939a8390701c81fff98814e22e63c
-
tomcat9-examples_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:b0dd5ef27f67bca9ab5c90e66e29e1e30ab376f6
-
tomcat9-user_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
sha:3f628b79fe55febb0e7cfa3c0edef9279fda6c5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.