[CLSA-2026:1789461431] Fix CVE(s): CVE-2026-65637, CVE-2026-68763
Type:
security
Severity:
Important
Release date:
2026-09-15 08:37:22 UTC
Description:
* SECURITY UPDATE: HTTP/2 requests without an authority bypassed strict SNI validation - the fix for CVE-2026-32990 required an authority only for CONNECT requests, so a request using any other method could omit it and evade the host check - debian/patches/CVE-2026-65637.patch: treat a missing serverName as a missing header for all non-CONNECT HTTP/2 requests in receivedEndOfHeaders() - CVE-2026-65637 * SECURITY UPDATE: Denial of service via an allocation leak in the HTTP/2 backlog - resetting a stream that was waiting on the connection window left its reservation counted in the backlog and its allocation unreturned, so repeated resets exhausted the connection window and stalled the connection - debian/patches/CVE-2026-68763.patch: remove a replaced stream from the backlog and return its unused allocation to the connection window, decrement backLogSize when allocating, and skip streams that can no longer write - CVE-2026-68763
Updated packages:
  • libtomcat9-embed-java_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:ac6bb0bc1ddd48d1868183573840294199ac33b3
  • libtomcat9-java_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:a938437e735e22bb7b332c5a3b094dee61cd207a
  • tomcat9_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:2406e57b4b888894f8e39f093884290592daa2b5
  • tomcat9-admin_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:2411440f8c959d1e8f2d54b9511b9cf077bb4cfa
  • tomcat9-common_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:11c259cec9daaf726d1100440d80a6ce780382c5
  • tomcat9-docs_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:89d9fbe7f00dfb9255f3ef8280686cb0dd336180
  • tomcat9-examples_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:be77e2ac3e27c4d89dd344fd7dd75428f85feabb
  • tomcat9-user_9.0.118-0+deb11u1+tuxcare.els1_all.deb
    sha:048bc6ed3855d069d367eafce25426609d745582
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.