openSUSE-SU-2026:21984-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21984-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/openSUSE-SU-2026:21984-1
Upstream
CVE (15)
  • CVE-2026-73581
  • CVE-2026-75973
  • CVE-2026-76183
  • CVE-2026-77756
  • CVE-2026-77762
  • CVE-2026-77791
  • CVE-2026-78383
  • CVE-2026-78437
  • CVE-2026-79677
  • CVE-2026-86243
  • CVE-2026-86246
  • CVE-2026-86247
  • CVE-2026-86248
  • CVE-2026-86350
  • CVE-2026-87022
Related
Published
2026-09-30T17:58:26Z
Modified
2026-10-01T18:23:24Z
Summary
Security update for libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10, tomcat11
Details

This update for libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10, tomcat11 fixes the following issues:

Security issues fixed:

  • CVE-2026-73581: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore (bsc#1282631).
  • CVE-2026-75973: improper authentication when Jakarta authentication is configured with SimpleAuthConfigProvider (bsc#1282630).
  • CVE-2026-76183: security constraints for any WebSocket endpoint can be bypassed (bsc#1282629).
  • CVE-2026-77756: inconsistent interpretation of HTTP requests allows an attacker to cause one request from another user to fail when Tomcat is located behind a reverse proxy (bsc#1282628).
  • CVE-2026-77762: Apache Tomcat: Stale HPACK emitter injects trailers (bsc#1282599).
  • CVE-2026-77791: uncontrolled resource consumption when sending WebSocket close message enabled a DoS attack (bsc#1282627).
  • CVE-2026-78383: allocation of resources without limits or throttling allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service (bsc#1282626).
  • CVE-2026-78437: incomplete cleanup allows a malformed request to potentially cause requests from another user to fail (bsc#1282625).
  • CVE-2026-79677: missing release of resource after effective lifetime and comparison using wrong factors allows for denial of service due to lost time outs for asynchronous WebSocket writes (bsc#1282624).
  • CVE-2026-86243: buffer overread during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash (bsc#1282623).
  • CVE-2026-86246: insecure ALLOW_CLIENT_RENEGOTIATION, NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX options enabled by default (bsc#1282622).
  • CVE-2026-86247: race condition allows client certificate verification requirements to be down-graded for some configurations (bsc#1282621).
  • CVE-2026-86248: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled (bsc#1282620).
  • CVE-2026-86350: HTTP/2 requests can cause request header mix-ups and HTTP request smuggling (bsc#1282787).
  • CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with (bsc#1282581).

Non security issue fixed:

  • package libtcnative-1-0-devel houses link to libtcnative-1.so instead of package libtcnative-1-0 (bsc#622430).

Changes for libtcnative-1-0:

  • Update to 1.3.9
  • Code: Remove call to ERR_remove_thread_state() from Windows specific code to allow building with OpenSSL 4.0.x. ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got removed in OpenSSL 4
  • Fix: Fix a potential crash when negotiating ALPN
  • If ALPN negotiation fails and failure is configured to use the last server protocol in the list, use it rather than the last protocol offered by the client
  • Fix: Add support for the extended range of options available from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned int (represented by a Java long) rather than a 32-bit unsigned int (represented by a Java int)
  • Code: Remove unused code
  • Ensure that per connection changes to certificate verification settings, e.g. to support client certificate authentication, do not modify the certificate verification settings for other connections
  • Fix: Fix a potential crash when configuring raw certificates
  • Fix: Avoid a potential crash with very long ALPN protocol names
  • Fix: Make the call to a CertificateVerifier more robust
  • Fix: Avoid a potential crash when processing OCSP URLs
  • Fix: Make the processing of OCSP responses more robust
  • Fix: Stricter OCSP handling when soft-fail is disabled
  • Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
  • Fix: Harden against the mis-use of Pool.destroy(long)
  • Code: The minimum supported OpenSSL version is now 3.0.x. OpenSSL 1.1.1 support was accidentally broken in 1.3.8. As no bug reports were receive for that failure and since both Debian and Ubuntu versions that used OpenSSL 1.1.1 have reached end of support, OpenSSL 1.1.1 is no longer supported
  • Update: OpenSSL 3.0.x is approaching end of support so the recommended version of OpenSSL (and the version that windows binaries will be built with) now follows the 3.5.x LTS branch
  • Fix: Switch to automatic configuration of DH parameters. Manual configuration attempts will be ignored
  • Code: Make setTmpECDHByCurveName() a NO-OP
  • Fix: Refactor extraction of ECDH curve name from the Certificate to avoid deprecated OpenSSL methods
  • Fix: Refactor the native implementation of SSL.getTime() to avoid the Y2038 problem in SSL_SESSION_get_time() when running on a verion of OpenSSL that includes the new SSL_SESSION_get_time_ex() method

Changes for libtcnative-2-0:

  • Upgrade to version 2.0.16
  • Code: Remove call to ERR_remove_thread_state() from Windows specific code to allow building with OpenSSL 4.0.x ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got removed in OpenSSL 4
  • Update: Remove support for Windows build on IA64 architecture (Itanium)
  • Update: Make x64 the default architecture for Windows build
  • Update: Make Windows 10 / 11 the default target version for Windows builds
  • Fix: Fix a potential crash when negotiating ALPN
  • Fix: If ALPN negotiation fails and failure is configured to use the last server protocol in the list, use it rather than the last protocol offered by the client
  • Fix: Add support for the extended range of options available from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned int (represented by a Java long) rather than a 32-bit unsigned int (represented by a Java int)
  • Code: Remove unused code
  • Fix: Ensure that per connection changes to certificate verification settings, e.g. to support client certificate authentication, do not modify the certificate verification settings for other connections
  • Fix: Fix a potential crash when configuring raw certificates
  • Fix: Avoid a potential crash with very long ALPN protocol names
  • Fix: Make the call to a CertificateVerifier more robust
  • Fix: Avoid a potential crash when processing OCSP URLs
  • Fix: Make the processing of OCSP responses more robust
  • Fix: Stricter OCSP handling when soft-fail is disabled
  • Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
  • Fix: Harden against the mis-use of Pool.destroy(long)

Changes for tomcat10:

  • Update to Tomcat 10.1.60
  • Fix: When a PersistentManager needs to reduce the number of active sessions, swap out the least recently used eligible sessions first. Pull request #1045 provided by sainadh777. (markt)
  • Fix: Align web.xml logging output with the new Context attribute urlPatternsProvidedInDecodedForm. (markt)
  • Fix: Improve robustness of DIGEST authentication to system clock jumps. (markt)
  • Add: Support multiple protocol header values (treat as a single merged header value) in the RemoteIpFilter and RemoteIpValve. (markt)
  • Fix: potential concurrency issues when loading/saving sessions from/to a session store. Custom Store implementations that do not extend StoreBase must implement the new getSessionStoreLock() method of the Store interface to ensure concurrency protection. The default method implementation provided only provides the pre-fix functionality. (markt)
  • Fix: Ensure that PersistentManager implementations that extend PersistentManagerBase do not swap out sessions that are associated with a request that is currently being processed. This includes not swapping out a session unless the session was created when activity tracking was enabled. (markt)
  • Fix: Ensure namespace attributes are XML escaped in WebDAV responses.
  • Fix: Resolve null or missing rewrite substitutions as an empty string, to align with the mod_rewrite behavior. (remm)
  • Add: a best efforts protection in the CrawlerSessionManagerValve against crawlers being associated with an authenticated session. (markt)
  • Fix: Clarify the meaning of various RewriteValve server variables and explicitly use the canonical context path for the CONTEXT_PATH server variable. (markt)
  • Fix: storeconfig not saving the path when a context is saved in server.xml. (remm)
  • Fix: WAR URLConnection should propagate use of caching. (remm)
  • Fix: Ensure resources are evicted from the static resource cache in the correct order. (markt)
  • Fix: When Jakarta Authentication is configured for a web application, cache the ServerAuthConfig in the Authenticator valve. This ensures web application specific settings are cached on a per web application basis.
  • Fix: 70203: Fix RegistrationListener notifications in Jakarta Authentication implementation. (markt)
  • Fix: Handle CGI scripts that write excessively to stdout after setting an HTTP error status code. (schultz)
  • Fix: Require the request to the login action during FORM authentication to be made using HTTP POST. (markt)
  • Fix: 70208: Make URL encoding more robust. Based on pull request #1065 by Chenjp. (markt)
  • Coyote
  • Fix: xreflection generated code stack overflow issue. (remm)
  • Fix: Align xreflection better with IntrospectionUtils. (remm)
  • Fix: In HTTP/2 after half closed (remote), any unexpected frame should be a stream error. (remm)
  • Fix: incorrect initial window size calculation when upgrading to HTTP/2. (remm)
  • Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
  • Fix: Only try and load the native library from the CATALINA_HOME system property when the property is set. (markt)
  • Fix: max connections enforcement after an enpoint resume. (remm)
  • Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
  • Add: length validation for ALPN protocol names. (markt)
  • Fix: Make FFM certificate verification more robust. (markt)
  • Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing failure as if no usable OCSP URLs were present. (markt)
  • Fix: Make the processing of OCSP responses more robust. (markt)
  • Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
  • Fix: Cleaner handling of AJP response headers which overflow the maximum message size. (remm)
  • Fix: Small per performance optimisation. Don't waste cycles swallowing an AJP response body when the connection is going to be closed. (markt)
  • Fix: OpenSSL support for CRLs when using OpenSSL trust with the server key held in a Java key store. (markt)
  • Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding header. (markt)
  • Fix: Ensure per request HTTP/2 bad request marker is cleared when the request is recycled. (markt)
  • Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
  • Fix: Revert earlier refactoring of HTTP/2 header field validation that moved it earlier since the refactoring made correct handling of invalid headers more difficult. (markt)
  • Fix: EL evaluation of some lambda expressions. (remm)
  • WebSocket
  • Fix: an exception when an automatic Pong response races with the closing of the WebSocket session. (moritzfl)
  • Fix: Harden the WebSocket client and use a SecureRandom when generating the Sec-WebSocket-Key header. (markt)
  • Fix: Improve robustness of client handshakes. (remm)
  • Fix: Ensure that WebSocket write timeouts apply to the complete message and are not lost if two writes have the same timeout. (markt)
  • Fix: Reduce CPU usage while sending WebSocket close message. (markt)
  • Fix: overly broad check that prevented request URIs containing literal { and } characters from being mapped to WebSocket end points. (markt)
  • Fix: handling of WebSocket messages with compressed payloads using per- message-deflate that have one or more non-final blocks where the BFINAL bit is set. (markt)
  • Fix: handling of per-message-deflate context takeover when receiving compressed WebSocket messages. (markt)
  • Web applications
  • Fix: Manager: Fix a potential concurrency issue when ordering sessions prior to displaying a list of session. (markt)
  • Docs: Wrap the RewriteRule regular expression syntax reference on narrow displays. Pull request #1044 by sainadh777. (markt)
  • Other
  • Update: Easymock to 5.7.0. (markt)
  • Update: bnd to 7.4.0. (markt)
  • Update: Tomcat Native to 2.0.16. (markt)
  • Add: Improvements to French translations. (remm)
  • Add: Improvements to Japanese translations provided by tak7iji and Ktamura.biz.80. (markt)
  • Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a positive integer. Zero or negative values previously caused an infinite loop or a NegativeArraySizeException during session state transfer. Pull request #1042 provided by lihongyi87. (markt)
  • Fix: Improve robustness of cloud membership providers if an error occurs fetching members. (remm)
  • jdbc-pool
  • Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to getConnection(String,String) rather than getConnection(). (markt)
  • Add: Log a warning if an attempt is made to obtain a connection with credentials when alternateUsernameAllowed is set to false. (markt)
  • Fix: Ensure StatementCache interceptor resets properties of cached statements between uses. (mark)

Changes for tomcat11:

  • Update to Tomcat 11.0.26
  • Fix: Improve the handling of AsyncContext.dispatch() when the Context attribute dispatchersUseEncodedPaths is set to false since the application has no control over the path used for the AsyncContext.dispatch(). Prior to this fix, paths containing literal '?' characters were truncated. (markt)
  • Fix: Ensure that capture groups from a RewriteCond always reflect the result of the current request. (markt)
  • Fix: When a PersistentManager needs to reduce the number of active sessions, swap out the least recently used eligible sessions first. Pull request #1045 provided by sainadh777. (markt)
  • Fix: Align web.xml logging output with the new Context attribute urlPatternsProvidedInDecodedForm. (markt)
  • Fix: Improve robustness of DIGEST authentication to system clock jumps. (markt)
  • Add: Support multiple protocol header values (treat as a single merged header value) in the RemoteIpFilter and RemoteIpValve. (markt)
  • Fix: potential concurrency issues when loading/saving sessions from/to a session store. Custom Store implementations that do not extend StoreBase must implement the new getSessionStoreLock() method of the Store interface to ensure concurrency protection. The default method implementation provided only provides the pre-fix functionality. (markt)
  • Fix: Ensure that PersistentManager implementations that extend PersistentManagerBase do not swap out sessions that are associated with a request that is currently being processed. This includes not swapping out a session unless the session was created when activity tracking was enabled. (markt)
  • Fix: Ensure namespace attributes are XML escaped in WebDAV responses.
  • Fix: Resolve null or missing rewrite substitutions as an empty string, to align with the mod_rewrite behavior. (remm)
  • Add: a best efforts protection in the CrawlerSessionManagerValve against crawlers being associated with an authenticated session. (markt)
  • Fix: Clarify the meaning of various RewriteValve server variables and explicitly use the canonical context path for the CONTEXT_PATH server variable. (markt)
  • Fix: storeconfig not saving the path when a context is saved in server.xml. (remm)
  • Fix: WAR URLConnection should propagate use of caching. (remm)
  • Fix: Ensure resources are evicted from the static resource cache in the correct order. (markt)
  • Fix: When Jakarta Authentication is configured for a web application, cache the ServerAuthConfig in the Authenticator valve. This ensures web application specific settings are cached on a per web application basis.
  • Fix: 70203: Fix RegistrationListener notifications in Jakarta Authentication implementation. (markt)
  • Fix: Handle CGI scripts that write excessively to stdout after setting an HTTP error status code. (schultz)
  • Fix: Require the request to the login action during FORM authentication to be made using HTTP POST. (markt)
  • Fix: 70208: Make URL encoding more robust. Based on pull request #1065 by Chenjp. (markt)
  • Coyote
  • Fix: parsing of client certificates that specify more than one OCSP responder for configurations that use OpenSSL-FFM. (markt)
  • Fix: xreflection generated code stack overflow issue. (remm)
  • Fix: Align xreflection better with IntrospectionUtils. (remm)
  • Fix: In HTTP/2 after half closed (remote), any unexpected frame should be a stream error. (remm)
  • Fix: incorrect initial window size calculation when upgrading to HTTP/2. (remm)
  • Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
  • Fix: Only try and load the native library from the CATALINA_HOME system property when the property is set. (markt)
  • Fix: max connections enforcement after an enpoint resume. (remm)
  • Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
  • Add: length validation for ALPN protocol names. (markt)
  • Fix: Make FFM certificate verification more robust. (markt)
  • Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing failure as if no usable OCSP URLs were present. (markt)
  • Fix: Make the processing of OCSP responses more robust. (markt)
  • Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
  • Fix: Cleaner handling of AJP response headers which overflow the maximum message size. (remm)
  • Fix: Small per performance optimisation. Don't waste cycles swallowing an AJP response body when the connection is going to be closed. (markt)
  • Fix: OpenSSL support for CRLs when using OpenSSL trust with the server key held in a Java key store. (markt)
  • Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding header. (markt)
  • Fix: Ensure per request HTTP/2 bad request marker is cleared when the request is recycled. (markt)
  • Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
  • Fix: Revert earlier refactoring of HTTP/2 header field validation that moved it earlier since the refactoring made correct handling of invalid headers more difficult. (markt)
  • Fix: EL evaluation of some lambda expressions. (remm)
  • WebSocket
  • Fix: an exception when an automatic Pong response races with the closing of the WebSocket session. (moritzfl)
  • Fix: Harden the WebSocket client and use a SecureRandom when generating the Sec-WebSocket-Key header. (markt)
  • Fix: Improve robustness of client handshakes. (remm)
  • Fix: Ensure that WebSocket write timeouts apply to the complete message and are not lost if two writes have the same timeout. (markt)
  • Fix: Reduce CPU usage while sending WebSocket close message. (markt)
  • Fix: overly broad check that prevented request URIs containing literal { and } characters from being mapped to WebSocket end points. (markt)
  • Fix: handling of WebSocket messages with compressed payloads using per- message-deflate that have one or more non-final blocks where the BFINAL bit is set. (markt)
  • Fix: handling of per-message-deflate context takeover when receiving compressed WebSocket messages. (markt)
  • Web applications
  • Fix: Manager: Fix a potential concurrency issue when ordering sessions prior to displaying a list of session. (markt)
  • Docs: Wrap the RewriteRule regular expression syntax reference on narrow displays. Pull request #1044 by sainadh777. (markt)
  • Other
  • Update: Easymock to 5.7.0. (markt)
  • Update: bnd to 7.4.0. (markt)
  • Update: Tomcat Native to 2.0.16. (markt)
  • Add: Improvements to French translations. (remm)
  • Add: Improvements to Japanese translations provided by tak7iji and Ktamura.biz.80. (markt)
  • Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a positive integer. Zero or negative values previously caused an infinite loop or a NegativeArraySizeException during session state transfer. Pull request #1042 provided by lihongyi87. (markt)
  • Fix: Improve robustness of cloud membership providers if an error occurs fetching members. (remm)
  • jdbc-pool
  • Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to getConnection(String,String) rather than getConnection(). (markt)
  • Add: Log a warning if an attempt is made to obtain a connection with credentials when alternateUsernameAllowed is set to false. (markt)
  • Fix: Ensure StatementCache interceptor resets properties of cached statements between uses. (mark)

Changes for tomcat:

  • Update to Tomcat 9.0.122
  • Fix: Improve the handling of AsyncContext.dispatch() when the Context attribute dispatchersUseEncodedPaths is set to false since the application has no control over the path used for the AsyncContext.dispatch(). Prior to this fix, paths containing literal '?' characters were truncated. (markt)
  • Fix: Ensure that capture groups from a RewriteCond always reflect the result of the current request. (markt)
  • Fix: When a PersistentManager needs to reduce the number of active sessions, swap out the least recently used eligible sessions first. Pull request #1045 provided by sainadh777. (markt)
  • Fix: Align web.xml logging output with the new Context attribute urlPatternsProvidedInDecodedForm. (markt)
  • Fix: Improve robustness of DIGEST authentication to system clock jumps. (markt)
  • Add: Support multiple protocol header values (treat as a single merged header value) in the RemoteIpFilter and RemoteIpValve. (markt)
  • Fix: potential concurrency issues when loading/saving sessions from/to a session store. Custom Store implementations that do not extend StoreBase must implement the new getSessionStoreLock() method of the Store interface to ensure concurrency protection. The default method implementation provided only provides the pre-fix functionality. (markt)
  • Fix: Ensure that PersistentManager implementations that extend PersistentManagerBase do not swap out sessions that are associated with a request that is currently being processed. As a result, it is now a requirement that the system property org.apache.catalina.session.StandardSession.ACTIVITY_CHECK is set to true (either explicitly or via STRICT_SERVLET_COMPLIANCE) if either minIdleSwap or maxIdleSwap are configured. (markt)
  • Coyote
  • Fix: xreflection generated code stack overflow issue. (remm)
  • Fix: Align xreflection better with IntrospectionUtils. (remm)
  • Fix: In HTTP/2 after half closed (remote), any unexpected frame should be a stream error. (remm)
  • Fix: incorrect initial window size calculation when upgrading to HTTP/2. (remm)
  • Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
  • Fix: Only try and load the native library from the CATALINA_HOME system property when the property is set. (markt)
  • Fix: max connections enforcement after an enpoint resume. (remm)
  • Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
  • Add: length validation for ALPN protocol names. (markt)
  • Fix: Make FFM certificate verification more robust. (markt)
  • Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing failure as if no usable OCSP URLs were present. (markt)
  • Fix: Make the processing of OCSP responses more robust. (markt)
  • Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
  • Fix: Cleaner handling of AJP response headers which overflow the maximum message size. (remm)
  • Fix: Small per performance optimisation. Don't waste cycles swallowing an AJP response body when the connection is going to be closed. (markt)
  • Fix: OpenSSL support for CRLs when using OpenSSL trust with the server key held in a Java key store. (markt)
  • Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding header. (markt)
  • Fix: Ensure per request HTTP/2 bad request marker is cleared when the request is recycled. (markt)
  • Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
  • Fix: Revert earlier refactoring of HTTP/2 header field validation that moved it earlier since the refactoring made correct handling of invalid headers more difficult. (markt)
  • Fix: EL evaluation of some lambda expressions. (remm)
  • WebSocket
  • Fix: an exception when an automatic Pong response races with the closing of the WebSocket session. (moritzfl)
  • Fix: Harden the WebSocket client and use a SecureRandom when generating the Sec-WebSocket-Key header. (markt)
  • Fix: Improve robustness of client handshakes. (remm)
  • Fix: Ensure that WebSocket write timeouts apply to the complete message and are not lost if two writes have the same timeout. (markt)
  • Fix: Reduce CPU usage while sending WebSocket close message. (markt)
  • Fix: overly broad check that prevented request URIs containing literal { and } characters from being mapped to WebSocket end points. (markt)
  • Fix: handling of WebSocket messages with compressed payloads using per- message-deflate that have one or more non-final blocks where the BFINAL bit is set. (markt)
  • Fix: handling of per-message-deflate context takeover when receiving compressed WebSocket messages. (markt)
  • Web applications
  • Fix: Manager: Fix a potential concurrency issue when ordering sessions prior to displaying a list of session. (markt)
  • Docs: Wrap the RewriteRule regular expression syntax reference on narrow displays. Pull request #1044 by sainadh777. (markt)
  • Other
  • Update: Easymock to 5.7.0. (markt)
  • Update: bnd to 7.4.0. (markt)
  • Update: Tomcat Native to 1.3.9. (markt)
  • Add: Improvements to French translations. (remm)
  • Add: Improvements to Japanese translations provided by tak7iji and Ktamura.biz.80. (markt)
  • Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a positive integer. Zero or negative values previously caused an infinite loop or a NegativeArraySizeException during session state transfer. Pull request #1042 provided by lihongyi87. (markt)
  • Fix: Improve robustness of cloud membership providers if an error occurs fetching members. (remm)
  • jdbc-pool
  • Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to getConnection(String,String) rather than getConnection(). (markt)
  • Add: Log a warning if an attempt is made to obtain a connection with credentials when alternateUsernameAllowed is set to false. (markt)
  • Fix: Ensure StatementCache interceptor resets properties of cached statements between uses. (mark)
References

Affected packages

openSUSE:Leap 16.0 / libtcnative-1-0

Package

Name
libtcnative-1-0
Purl
pkg:rpm/opensuse/libtcnative-1-0&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.9-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "libtcnative-1-0": "1.3.9-160000.1.1",
            "libtcnative-1-0-devel": "1.3.9-160000.1.1",
            "libtcnative-2-0": "2.0.16-160000.1.1",
            "libtcnative-2-0-devel": "2.0.16-160000.1.1",
            "tomcat": "9.0.122-160000.1.1",
            "tomcat-admin-webapps": "9.0.122-160000.1.1",
            "tomcat-docs-webapp": "9.0.122-160000.1.1",
            "tomcat-el-3_0-api": "9.0.122-160000.1.1",
            "tomcat-embed": "9.0.122-160000.1.1",
            "tomcat-javadoc": "9.0.122-160000.1.1",
            "tomcat-jsp-2_3-api": "9.0.122-160000.1.1",
            "tomcat-jsvc": "9.0.122-160000.1.1",
            "tomcat-lib": "9.0.122-160000.1.1",
            "tomcat-servlet-4_0-api": "9.0.122-160000.1.1",
            "tomcat-webapps": "9.0.122-160000.1.1",
            "tomcat10": "10.1.60-160000.1.1",
            "tomcat10-admin-webapps": "10.1.60-160000.1.1",
            "tomcat10-doc": "10.1.60-160000.1.1",
            "tomcat10-docs-webapp": "10.1.60-160000.1.1",
            "tomcat10-el-5_0-api": "10.1.60-160000.1.1",
            "tomcat10-embed": "10.1.60-160000.1.1",
            "tomcat10-jsp-3_1-api": "10.1.60-160000.1.1",
            "tomcat10-jsvc": "10.1.60-160000.1.1",
            "tomcat10-lib": "10.1.60-160000.1.1",
            "tomcat10-servlet-6_0-api": "10.1.60-160000.1.1",
            "tomcat10-webapps": "10.1.60-160000.1.1",
            "tomcat11": "11.0.26-160000.1.1",
            "tomcat11-admin-webapps": "11.0.26-160000.1.1",
            "tomcat11-doc": "11.0.26-160000.1.1",
            "tomcat11-docs-webapp": "11.0.26-160000.1.1",
            "tomcat11-el-6_0-api": "11.0.26-160000.1.1",
            "tomcat11-embed": "11.0.26-160000.1.1",
            "tomcat11-jsp-4_0-api": "11.0.26-160000.1.1",
            "tomcat11-jsvc": "11.0.26-160000.1.1",
            "tomcat11-lib": "11.0.26-160000.1.1",
            "tomcat11-servlet-6_1-api": "11.0.26-160000.1.1",
            "tomcat11-webapps": "11.0.26-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21984-1.json"

openSUSE:Leap 16.0 / libtcnative-2-0

Package

Name
libtcnative-2-0
Purl
pkg:rpm/opensuse/libtcnative-2-0&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.16-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "libtcnative-1-0": "1.3.9-160000.1.1",
            "libtcnative-1-0-devel": "1.3.9-160000.1.1",
            "libtcnative-2-0": "2.0.16-160000.1.1",
            "libtcnative-2-0-devel": "2.0.16-160000.1.1",
            "tomcat": "9.0.122-160000.1.1",
            "tomcat-admin-webapps": "9.0.122-160000.1.1",
            "tomcat-docs-webapp": "9.0.122-160000.1.1",
            "tomcat-el-3_0-api": "9.0.122-160000.1.1",
            "tomcat-embed": "9.0.122-160000.1.1",
            "tomcat-javadoc": "9.0.122-160000.1.1",
            "tomcat-jsp-2_3-api": "9.0.122-160000.1.1",
            "tomcat-jsvc": "9.0.122-160000.1.1",
            "tomcat-lib": "9.0.122-160000.1.1",
            "tomcat-servlet-4_0-api": "9.0.122-160000.1.1",
            "tomcat-webapps": "9.0.122-160000.1.1",
            "tomcat10": "10.1.60-160000.1.1",
            "tomcat10-admin-webapps": "10.1.60-160000.1.1",
            "tomcat10-doc": "10.1.60-160000.1.1",
            "tomcat10-docs-webapp": "10.1.60-160000.1.1",
            "tomcat10-el-5_0-api": "10.1.60-160000.1.1",
            "tomcat10-embed": "10.1.60-160000.1.1",
            "tomcat10-jsp-3_1-api": "10.1.60-160000.1.1",
            "tomcat10-jsvc": "10.1.60-160000.1.1",
            "tomcat10-lib": "10.1.60-160000.1.1",
            "tomcat10-servlet-6_0-api": "10.1.60-160000.1.1",
            "tomcat10-webapps": "10.1.60-160000.1.1",
            "tomcat11": "11.0.26-160000.1.1",
            "tomcat11-admin-webapps": "11.0.26-160000.1.1",
            "tomcat11-doc": "11.0.26-160000.1.1",
            "tomcat11-docs-webapp": "11.0.26-160000.1.1",
            "tomcat11-el-6_0-api": "11.0.26-160000.1.1",
            "tomcat11-embed": "11.0.26-160000.1.1",
            "tomcat11-jsp-4_0-api": "11.0.26-160000.1.1",
            "tomcat11-jsvc": "11.0.26-160000.1.1",
            "tomcat11-lib": "11.0.26-160000.1.1",
            "tomcat11-servlet-6_1-api": "11.0.26-160000.1.1",
            "tomcat11-webapps": "11.0.26-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21984-1.json"

openSUSE:Leap 16.0 / tomcat

Package

Name
tomcat
Purl
pkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
9.0.122-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "libtcnative-1-0": "1.3.9-160000.1.1",
            "libtcnative-1-0-devel": "1.3.9-160000.1.1",
            "libtcnative-2-0": "2.0.16-160000.1.1",
            "libtcnative-2-0-devel": "2.0.16-160000.1.1",
            "tomcat": "9.0.122-160000.1.1",
            "tomcat-admin-webapps": "9.0.122-160000.1.1",
            "tomcat-docs-webapp": "9.0.122-160000.1.1",
            "tomcat-el-3_0-api": "9.0.122-160000.1.1",
            "tomcat-embed": "9.0.122-160000.1.1",
            "tomcat-javadoc": "9.0.122-160000.1.1",
            "tomcat-jsp-2_3-api": "9.0.122-160000.1.1",
            "tomcat-jsvc": "9.0.122-160000.1.1",
            "tomcat-lib": "9.0.122-160000.1.1",
            "tomcat-servlet-4_0-api": "9.0.122-160000.1.1",
            "tomcat-webapps": "9.0.122-160000.1.1",
            "tomcat10": "10.1.60-160000.1.1",
            "tomcat10-admin-webapps": "10.1.60-160000.1.1",
            "tomcat10-doc": "10.1.60-160000.1.1",
            "tomcat10-docs-webapp": "10.1.60-160000.1.1",
            "tomcat10-el-5_0-api": "10.1.60-160000.1.1",
            "tomcat10-embed": "10.1.60-160000.1.1",
            "tomcat10-jsp-3_1-api": "10.1.60-160000.1.1",
            "tomcat10-jsvc": "10.1.60-160000.1.1",
            "tomcat10-lib": "10.1.60-160000.1.1",
            "tomcat10-servlet-6_0-api": "10.1.60-160000.1.1",
            "tomcat10-webapps": "10.1.60-160000.1.1",
            "tomcat11": "11.0.26-160000.1.1",
            "tomcat11-admin-webapps": "11.0.26-160000.1.1",
            "tomcat11-doc": "11.0.26-160000.1.1",
            "tomcat11-docs-webapp": "11.0.26-160000.1.1",
            "tomcat11-el-6_0-api": "11.0.26-160000.1.1",
            "tomcat11-embed": "11.0.26-160000.1.1",
            "tomcat11-jsp-4_0-api": "11.0.26-160000.1.1",
            "tomcat11-jsvc": "11.0.26-160000.1.1",
            "tomcat11-lib": "11.0.26-160000.1.1",
            "tomcat11-servlet-6_1-api": "11.0.26-160000.1.1",
            "tomcat11-webapps": "11.0.26-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21984-1.json"

openSUSE:Leap 16.0 / tomcat10

Package

Name
tomcat10
Purl
pkg:rpm/opensuse/tomcat10&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.1.60-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "libtcnative-1-0": "1.3.9-160000.1.1",
            "libtcnative-1-0-devel": "1.3.9-160000.1.1",
            "libtcnative-2-0": "2.0.16-160000.1.1",
            "libtcnative-2-0-devel": "2.0.16-160000.1.1",
            "tomcat": "9.0.122-160000.1.1",
            "tomcat-admin-webapps": "9.0.122-160000.1.1",
            "tomcat-docs-webapp": "9.0.122-160000.1.1",
            "tomcat-el-3_0-api": "9.0.122-160000.1.1",
            "tomcat-embed": "9.0.122-160000.1.1",
            "tomcat-javadoc": "9.0.122-160000.1.1",
            "tomcat-jsp-2_3-api": "9.0.122-160000.1.1",
            "tomcat-jsvc": "9.0.122-160000.1.1",
            "tomcat-lib": "9.0.122-160000.1.1",
            "tomcat-servlet-4_0-api": "9.0.122-160000.1.1",
            "tomcat-webapps": "9.0.122-160000.1.1",
            "tomcat10": "10.1.60-160000.1.1",
            "tomcat10-admin-webapps": "10.1.60-160000.1.1",
            "tomcat10-doc": "10.1.60-160000.1.1",
            "tomcat10-docs-webapp": "10.1.60-160000.1.1",
            "tomcat10-el-5_0-api": "10.1.60-160000.1.1",
            "tomcat10-embed": "10.1.60-160000.1.1",
            "tomcat10-jsp-3_1-api": "10.1.60-160000.1.1",
            "tomcat10-jsvc": "10.1.60-160000.1.1",
            "tomcat10-lib": "10.1.60-160000.1.1",
            "tomcat10-servlet-6_0-api": "10.1.60-160000.1.1",
            "tomcat10-webapps": "10.1.60-160000.1.1",
            "tomcat11": "11.0.26-160000.1.1",
            "tomcat11-admin-webapps": "11.0.26-160000.1.1",
            "tomcat11-doc": "11.0.26-160000.1.1",
            "tomcat11-docs-webapp": "11.0.26-160000.1.1",
            "tomcat11-el-6_0-api": "11.0.26-160000.1.1",
            "tomcat11-embed": "11.0.26-160000.1.1",
            "tomcat11-jsp-4_0-api": "11.0.26-160000.1.1",
            "tomcat11-jsvc": "11.0.26-160000.1.1",
            "tomcat11-lib": "11.0.26-160000.1.1",
            "tomcat11-servlet-6_1-api": "11.0.26-160000.1.1",
            "tomcat11-webapps": "11.0.26-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21984-1.json"

openSUSE:Leap 16.0 / tomcat11

Package

Name
tomcat11
Purl
pkg:rpm/opensuse/tomcat11&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
11.0.26-160000.1.1

Ecosystem specific

{
    "binaries": [
        {
            "libtcnative-1-0": "1.3.9-160000.1.1",
            "libtcnative-1-0-devel": "1.3.9-160000.1.1",
            "libtcnative-2-0": "2.0.16-160000.1.1",
            "libtcnative-2-0-devel": "2.0.16-160000.1.1",
            "tomcat": "9.0.122-160000.1.1",
            "tomcat-admin-webapps": "9.0.122-160000.1.1",
            "tomcat-docs-webapp": "9.0.122-160000.1.1",
            "tomcat-el-3_0-api": "9.0.122-160000.1.1",
            "tomcat-embed": "9.0.122-160000.1.1",
            "tomcat-javadoc": "9.0.122-160000.1.1",
            "tomcat-jsp-2_3-api": "9.0.122-160000.1.1",
            "tomcat-jsvc": "9.0.122-160000.1.1",
            "tomcat-lib": "9.0.122-160000.1.1",
            "tomcat-servlet-4_0-api": "9.0.122-160000.1.1",
            "tomcat-webapps": "9.0.122-160000.1.1",
            "tomcat10": "10.1.60-160000.1.1",
            "tomcat10-admin-webapps": "10.1.60-160000.1.1",
            "tomcat10-doc": "10.1.60-160000.1.1",
            "tomcat10-docs-webapp": "10.1.60-160000.1.1",
            "tomcat10-el-5_0-api": "10.1.60-160000.1.1",
            "tomcat10-embed": "10.1.60-160000.1.1",
            "tomcat10-jsp-3_1-api": "10.1.60-160000.1.1",
            "tomcat10-jsvc": "10.1.60-160000.1.1",
            "tomcat10-lib": "10.1.60-160000.1.1",
            "tomcat10-servlet-6_0-api": "10.1.60-160000.1.1",
            "tomcat10-webapps": "10.1.60-160000.1.1",
            "tomcat11": "11.0.26-160000.1.1",
            "tomcat11-admin-webapps": "11.0.26-160000.1.1",
            "tomcat11-doc": "11.0.26-160000.1.1",
            "tomcat11-docs-webapp": "11.0.26-160000.1.1",
            "tomcat11-el-6_0-api": "11.0.26-160000.1.1",
            "tomcat11-embed": "11.0.26-160000.1.1",
            "tomcat11-jsp-4_0-api": "11.0.26-160000.1.1",
            "tomcat11-jsvc": "11.0.26-160000.1.1",
            "tomcat11-lib": "11.0.26-160000.1.1",
            "tomcat11-servlet-6_1-api": "11.0.26-160000.1.1",
            "tomcat11-webapps": "11.0.26-160000.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21984-1.json"