[CLSA-2026:1780649787] Fix of 7 CVEs
Type:
security
Severity:
Low
Release date:
2026-06-05 08:56:53 UTC
Description:
* SECURITY UPDATE: fix the handling of invalid users with DIGEST authentication - debian/patches/CVE-2026-43512.patch: fix the handling of invalid users with DIGEST authentication - CVE-2026-43512 * SECURITY UPDATE: add case sensitive attribute to LockOutRealm - debian/patches/CVE-2026-43513.patch: add case sensitive attribute to LockOutRealm - CVE-2026-43513 * SECURITY UPDATE: switch AJP secret comparison to a constant time algorithm - debian/patches/CVE-2026-43514.patch: switch AJP secret comparison to a constant time algorithm - CVE-2026-43514 * SECURITY UPDATE: ensure RealmBase finds all matching extension based constraints - debian/patches/CVE-2026-43515.patch: ensure RealmBase finds all matching extension based constraints - CVE-2026-43515 * SECURITY UPDATE: add a configurable limit for WebDAV XML request bodies - debian/patches/CVE-2026-41284.patch: add a configurable limit for WebDAV XML request bodies - CVE-2026-41284 * SECURITY UPDATE: fix WebSocket + proxy + DIGEST auth on proxy - debian/patches/CVE-2026-42498.patch: fix WebSocket + proxy + DIGEST auth on proxy - CVE-2026-42498 * SECURITY UPDATE: HTTP/2 header filtering - validate decoded HPACK names/values against RFC 7230 token/field-vchar/field-content rules - debian/patches/CVE-2026-41293.patch: HTTP/2 header filtering - validate decoded HPACK names/values against RFC 7230 token/field-vchar/field-content rules - CVE-2026-41293 * Build: refresh debian/test_certs/ test fixtures (CA + RSA/EC server certs + client cert) — upstream localhost-rsa.jks is expired since 2025-02-16 and 8.5.x is no longer rotated; new fixtures are signed by a fresh self-signed CA with 10-year validity, applied via the existing TEST_CERTS_DIR overlay in debian/rules.
Updated packages:
  • libtomcat8-embed-java_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:dfadbc547ef9e8e85824d565c4244ce2f49b4293
  • libtomcat8-java_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:3e2d4d92ca3abfec6d1b7ee03bcceeac8c6e590e
  • tomcat8_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:045418c97d47b39532a4a8c7ad40aa477c2b26e2
  • tomcat8-admin_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:df0164c53ea02d84b8e3788e15cb1969e8cec166
  • tomcat8-common_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:20616509c062c3e07dfc9c56efa9b4373114aa92
  • tomcat8-docs_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:c0cc65bbb9af6ffefc7b9e559b93d59b60cd0675
  • tomcat8-examples_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:a5fb720d2a9fd13749e5ac5fb0fc3af5812de8ba
  • tomcat8-user_8.5.100-1ubuntu1~18.04.1+tuxcare.els3_all.deb
    sha:166635290bcb5db6baac0aed1cfe2cdd9874dfb5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.