[CLSA-2026:1774460133] Fix CVE(s): CVE-2025-66614
Type:
security
Severity:
Critical
Release date:
2026-03-25 17:35:37 UTC
Description:
* SECURITY UPDATE: client certificate authentication bypass through mismatched SNI and HTTP Host header - debian/patches/CVE-2025-66614.patch: Add strictSNI connector attribute and implement SNI/protocol host name matching for NIO, NIO2, and APR connectors; prevent requests being served by mismatched SSLHostConfig when SNI host and HTTP Host header differ. - CVE-2025-66614 * Fix ObjectStreamClass cache clearing for JDK 11.0.16+ - debian/patches/fix-ObjectStreamClass-cache-clearing.patch: Use instanceof guard in WebappClassLoaderBase.clearCache() instead of direct cast to Map, fixing ClassCastException with newer JDK where ObjectStreamClass$Caches fields were changed from Map to ClassValue (JDK-8277072). * Regenerate expired test SSL certificates - debian/test_certs/: Regenerated ca.jks, localhost.jks, localhost-copy1.jks, user1.jks and PEM files. The user1 certificate expired on 2025-08-15, causing TestClientCert SSLHandshakeException failures. * Fix flaky test infrastructure on build farm - debian/patches/fix-test-hostname-resolution.patch: Skip TestStandardSessionIntegration, TestGroupChannelSenderConnections, TestGroupChannelStartStop, and TestGroupChannelOptionFlag when build node hostname cannot be resolved via DNS (UnknownHostException). - debian/patches/CVE-2025-66614.patch: Skip testSni on APR connector since it uses JSSE-style SSLHostConfig incompatible with OpenSSL backend.
Updated packages:
  • libtomcat9-embed-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:462bf56d0917234a7479b8eb6c39dc2f0cf78174
  • libtomcat9-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:b8cd5898c586ec6925cb301536a432866802759a
  • tomcat9_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:93c9aa30358330ceebf4416ef75c7f0dc19d8c5c
  • tomcat9-admin_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:d8637e9260591d377b372634df3ece0e0ba865a5
  • tomcat9-common_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:629bd307b9b9a502863f24114ca164e37c5a1b26
  • tomcat9-docs_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:2441851216f327f1bd8aedb776b54f2d1688386b
  • tomcat9-examples_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:544445708ba5b8abbd17e36e10eee50f73ecb08b
  • tomcat9-user_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
    sha:ba4ba36d314c566b797a7bbb5c81d13737c85e3c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.