Release date:
2026-07-31 11:31:29 UTC
Description:
- CVE-2026-55955: add replay protection to the cluster EncryptInterceptor by
encrypting a trusted timestamp with each message and rejecting duplicate,
stale or future messages via the new replayWindowTime and
replayWindowMessageCount attributes (upstream tomcat 9.0.119). The default
encryptionAlgorithm also changes from AES/CBC/PKCS5Padding to
AES/GCM/NoPadding, because the replay protection is only effective for
non-malleable algorithms. NOTE: this changes the encrypted cluster message
format, so a cluster using EncryptInterceptor must be restarted as a whole,
not node by node
Updated packages:
-
tomcat-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:21e347ab42f811db8fe5b40e56488a7d14bfe4ce4ac3a5dd1eacdd070562f0d0
-
tomcat-admin-webapps-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:9bffef294155e7c57073b975d8afc49bfbbad0ca140c710d939213cf7e0d031b
-
tomcat-docs-webapp-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:a438e6f42ec83476723155b69b1a7a7c7b922cb90174a1b0a0e1025de29a1349
-
tomcat-el-3.0-api-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:f481ccac23b0e81ccaa6bad00b079bd11331c8fc7225cc67901b190efaadd747
-
tomcat-jsp-2.3-api-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:8b9aa955e74c03cd9dac7a6e0f84da21ee60bd5d81865824d3049e81fabf1400
-
tomcat-lib-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:00f558e0d469d3e078510430268fd191c61a216d214c58fc3f7d3a981aee8340
-
tomcat-servlet-4.0-api-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:3bbd862d46a0bd9f1ff195c49e4961f308f50f1b3093b136caf3e7387b7cde82
-
tomcat-webapps-9.0.87-3.el9_6.3.tuxcare.els12.noarch.rpm
sha:4cf451724e60ce2aa1cae1cc74db0452510d4d7bc3e4cdc399d3cd3926873586
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.