Alerts This Week
Warning Icon 1 938
Alerts This Week
Warning Icon 1 938

Ubuntu 24.04 Apache Tomcat Connectors Critical Denial of Service USN-8369-1

ubuntu
Calendar Grey June 2, 2026
Dist Ubuntu Esm H88
Apache Tomcat Connectors in Ubuntu have a critical issue that can expose sensitive data or may cause a denial of service.
Apache Tomcat Connectors could allow local users to expose sensitive information or cause a denial of service.

Summary

Apache Tomcat Connectors could allow local users to expose sensitive

information or cause a denial of service.

Software Description:

- libapache-mod-jk: Apache 2 connector for the Tomcat Java servlet engine

Details:

It was discovered that Apache Tomcat Connectors used incorrect default

permissions for shared memory on Unix-like systems. A local attacker

could possibly use this issue to view or modify mod_jk configuration

data in shared memory, resulting in sensitive information exposure or a

denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
  libapache2-mod-jk               1:1.2.49-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 22.04 LTS
  libapache2-mod-jk               1:1.2.48-1ubuntu0.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  libapache2-mod-jk               1:1.2.46-1ubuntu0.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libapache2-mod-jk               1:1.2.43-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libapache2-mod-jk               1:1.2.41-1ubuntu0.1~esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8369-1

CVE-2024-46544

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8369-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here