[CLSA-2026:1784541319] Fix CVE(s): CVE-2026-55957
Type:
security
Severity:
Important
Release date:
2026-07-20 09:55:41 UTC
Description:
* SECURITY UPDATE: JNDIRealm credential validation bypass when configured to use GSSAPI - debian/patches/CVE-2026-55957.patch: in bindAsUser preserve the current SASL environment, move userCredentialsAdd inside the try, strip Context.SECURITY_AUTHENTICATION="GSSAPI" before the LDAP bind so the provided username/password are actually validated, and restore the original SASL setting in a finally block along with userCredentialsRemove. Also updates docs/config/realm.xml to document that GSSAPI is skipped for calls made via HttpServletRequest.login(String, String). - CVE-2026-55957
CVEs fixed:
Updated packages:
  • libtomcat9-embed-java_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:0737236b64bc9ebddc3bf2552fe76ef6d1a43cd7
  • libtomcat9-java_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:38f23df4d336490568460c361627a807ebc7cb19
  • tomcat9_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:748336b6a6db61e2bc1b62a9b69228faf6946d61
  • tomcat9-admin_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:9d37e27bcadbce1550c46ee8e3c4093b654056b2
  • tomcat9-common_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:8b92a4f423bbc72593f0f567a2d60b5b94a42ebf
  • tomcat9-docs_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:575d49e9fc6939a8390701c81fff98814e22e63c
  • tomcat9-examples_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:b0dd5ef27f67bca9ab5c90e66e29e1e30ab376f6
  • tomcat9-user_9.0.31-1ubuntu0.9+tuxcare.els5_all.deb
    sha:3f628b79fe55febb0e7cfa3c0edef9279fda6c5c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.