Release date:
2026-03-25 17:35:37 UTC
Description:
* SECURITY UPDATE: client certificate authentication bypass through mismatched
SNI and HTTP Host header
- debian/patches/CVE-2025-66614.patch: Add strictSNI connector attribute and
implement SNI/protocol host name matching for NIO, NIO2, and APR
connectors; prevent requests being served by mismatched SSLHostConfig when
SNI host and HTTP Host header differ.
- CVE-2025-66614
* Fix ObjectStreamClass cache clearing for JDK 11.0.16+
- debian/patches/fix-ObjectStreamClass-cache-clearing.patch: Use instanceof
guard in WebappClassLoaderBase.clearCache() instead of direct cast to Map,
fixing ClassCastException with newer JDK where ObjectStreamClass$Caches
fields were changed from Map to ClassValue (JDK-8277072).
* Regenerate expired test SSL certificates
- debian/test_certs/: Regenerated ca.jks, localhost.jks, localhost-copy1.jks,
user1.jks and PEM files. The user1 certificate expired on 2025-08-15,
causing TestClientCert SSLHandshakeException failures.
* Fix flaky test infrastructure on build farm
- debian/patches/fix-test-hostname-resolution.patch: Skip
TestStandardSessionIntegration, TestGroupChannelSenderConnections,
TestGroupChannelStartStop, and TestGroupChannelOptionFlag when build
node hostname cannot be resolved via DNS (UnknownHostException).
- debian/patches/CVE-2025-66614.patch: Skip testSni on APR connector
since it uses JSSE-style SSLHostConfig incompatible with OpenSSL backend.
Updated packages:
-
libtomcat9-embed-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:462bf56d0917234a7479b8eb6c39dc2f0cf78174
-
libtomcat9-java_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:b8cd5898c586ec6925cb301536a432866802759a
-
tomcat9_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:93c9aa30358330ceebf4416ef75c7f0dc19d8c5c
-
tomcat9-admin_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:d8637e9260591d377b372634df3ece0e0ba865a5
-
tomcat9-common_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:629bd307b9b9a502863f24114ca164e37c5a1b26
-
tomcat9-docs_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:2441851216f327f1bd8aedb776b54f2d1688386b
-
tomcat9-examples_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:544445708ba5b8abbd17e36e10eee50f73ecb08b
-
tomcat9-user_9.0.16-3ubuntu0.18.04.2+tuxcare.els14_all.deb
sha:ba4ba36d314c566b797a7bbb5c81d13737c85e3c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.