Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Oracle Linux 8: ELSA-2025-11333 tomcat Important DoS and RCE Issues

oracle
Calendar Grey July 17, 2025
Oracle Linux Logo Esm H88
Critical vulnerabilities related to DoS and RCE have been patched in Oracle Linux pertaining to Tomcat. It is strongly recommended that impacted applications be updated without delay.
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:

Summary

[1:9.0.87-1.el8_10.4] - Resolves: RHEL-91761 tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650) - Resolves: RHEL-71971 tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337)

SRPMs

http://oss.oracle.com/ol8/SRPMS-updates/tomcat-9.0.87-1.el8_10.4.src.rpm

x86_64

tomcat-9.0.87-1.el8_10.4.noarch.rpm tomcat-admin-webapps-9.0.87-1.el8_10.4.noarch.rpm tomcat-docs-webapp-9.0.87-1.el8_10.4.noarch.rpm tomcat-el-3.0-api-9.0.87-1.el8_10.4.noarch.rpm tomcat-jsp-2.3-api-9.0.87-1.el8_10.4.noarch.rpm tomcat-lib-9.0.87-1.el8_10.4.noarch.rpm tomcat-servlet-4.0-api-9.0.87-1.el8_10.4.noarch.rpm tomcat-webapps-9.0.87-1.el8_10.4.noarch.rpm

aarch64

tomcat-9.0.87-1.el8_10.4.noarch.rpm tomcat-admin-webapps-9.0.87-1.el8_10.4.noarch.rpm tomcat-docs-webapp-9.0.87-1.el8_10.4.noarch.rpm tomcat-el-3.0-api-9.0.87-1.el8_10.4.noarch.rpm tomcat-jsp-2.3-api-9.0.87-1.el8_10.4.noarch.rpm tomcat-lib-9.0.87-1.el8_10.4.noarch.rpm tomcat-servlet-4.0-api-9.0.87-1.el8_10.4.noarch.rpm tomcat-webapps-9.0.87-1.el8_10.4.noarch.rpm

Severity
important
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2024-56337 CVE-2025-31650

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here