Release date:
2026-09-15 08:37:22 UTC
Description:
* SECURITY UPDATE: HTTP/2 requests without an authority bypassed strict
SNI validation - the fix for CVE-2026-32990 required an authority only
for CONNECT requests, so a request using any other method could omit it
and evade the host check
- debian/patches/CVE-2026-65637.patch: treat a missing serverName as a
missing header for all non-CONNECT HTTP/2 requests in
receivedEndOfHeaders()
- CVE-2026-65637
* SECURITY UPDATE: Denial of service via an allocation leak in the HTTP/2
backlog - resetting a stream that was waiting on the connection window
left its reservation counted in the backlog and its allocation
unreturned, so repeated resets exhausted the connection window and
stalled the connection
- debian/patches/CVE-2026-68763.patch: remove a replaced stream from the
backlog and return its unused allocation to the connection window,
decrement backLogSize when allocating, and skip streams that can no
longer write
- CVE-2026-68763
Updated packages:
-
libtomcat9-embed-java_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:ac6bb0bc1ddd48d1868183573840294199ac33b3
-
libtomcat9-java_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:a938437e735e22bb7b332c5a3b094dee61cd207a
-
tomcat9_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:2406e57b4b888894f8e39f093884290592daa2b5
-
tomcat9-admin_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:2411440f8c959d1e8f2d54b9511b9cf077bb4cfa
-
tomcat9-common_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:11c259cec9daaf726d1100440d80a6ce780382c5
-
tomcat9-docs_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:89d9fbe7f00dfb9255f3ef8280686cb0dd336180
-
tomcat9-examples_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:be77e2ac3e27c4d89dd344fd7dd75428f85feabb
-
tomcat9-user_9.0.118-0+deb11u1+tuxcare.els1_all.deb
sha:048bc6ed3855d069d367eafce25426609d745582
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.