[CLSA-2026:1786484994] Fix CVE(s): CVE-2026-29146
Type:
security
Severity:
Important
Release date:
2026-08-11 21:50:06 UTC
Description:
* SECURITY UPDATE: padding oracle attack in the Tribes EncryptInterceptor - debian/patches/CVE-2026-29146.patch: restrict the cipher algorithm modes accepted by setEncryptionAlgorithm and change the implicit mode to GCM/NoPadding in java/org/apache/catalina/tribes/group/interceptors/EncryptInterceptor.java - CVE-2026-29146
CVEs fixed:
Updated packages:
  • libtomcat8-embed-java_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:45d8a5076b51806d7b87e28f6bd9878823dd4e44
  • libtomcat8-java_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:bad84f0d555015722ee04070ae8fb0459dfa77cc
  • tomcat8_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:8f41b65b7db513584ec5d2caa2e1fb9e1ba434c8
  • tomcat8-admin_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:a30bdf37dd02c2284be39e88b985616ee8b9e6d8
  • tomcat8-common_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:8a6ab117589d820d949b0831da29e22d1c67ff65
  • tomcat8-docs_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:caf69bfa4ab07124c46ce03fe3e5eb84d1fdb799
  • tomcat8-examples_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:d6034fe5a5be77a5553fe53c2ac1a1f6c9b1001e
  • tomcat8-user_8.5.100-1ubuntu1~18.04.1+tuxcare.els5_all.deb
    sha:f6187de0f69d55307220a1ef80985c46f7ff3fa2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.