Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Tomcat.. ========================================================================== Ubuntu Security Notice USN-8417-1 June 10, 2026 tomcat9, tomcat10 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Tomcat. Software Description: - tomcat10: Servlet and JSP engine - tomcat9: Servlet and JSP engine Details: It was discovered that Tomcat did not properly limit the size of WebDAV LOCK and PROPFIND request bodies. A remote attacker could use this issue to cause Tomcat to consume excessive memory, resulting in a denial of service. (CVE-2026-41284) It was discovered that Tomcat incorrectly validated HTTP/2 header fields. A remote attacker could use this issue to cause Tomcat to crash or possibly execute arbitrary code. (CVE-2026-41293) It was discovered that Tomcat did not properly clear HTTP authentication headers during WebSocket connection upgrades and redirects. A remote attacker could use this issue to obtain sensitive credentials. (CVE-2026-42498) It was discovered that Tomcat incorrectly handled digest authentication. A remote attacker could possibly use this issue to bypass authentication restrictions. (CVE-2026-43512) It was discovered that Tomcat incorrectly handled case sensitivity in LockOutRealm. A remote attacker could possibly use this issue to bypass account lockout protections and obtain sensitive information. (CVE-2026-43513) It was discovered that Tomcat incorrectly handled authorization when multiple method constraints defined the same HTTP method. A remote attacker could possibly use this issue to bypass authorization restrictions. (CVE-2026-43515) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS libtomcat10-embed-java 10.1.40-1ubuntu1.26.04.1 libtomcat10-java 10.1.40-1ubuntu1.26.04.1 libtomcat9-java 9.0.115-1ubuntu0.1 tomcat10 10.1.40-1ubuntu1.26.04.1 Ubuntu 25.10 libtomcat10-embed-java 10.1.40-1ubuntu1.25.10.1 libtomcat10-java 10.1.40-1ubuntu1.25.10.1 libtomcat9-java 9.0.95-1ubuntu1.1 tomcat10 10.1.40-1ubuntu1.25.10.1 Ubuntu 24.04 LTS libtomcat10-embed-java 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro libtomcat10-java 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro libtomcat9-java 9.0.70-2ubuntu0.1+esm3 Available with Ubuntu Pro tomcat10 10.1.16-1ubuntu0.1~esm4 Available with Ubuntu Pro Ubuntu 22.04 LTS libtomcat9-embed-java 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro libtomcat9-java 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro tomcat9 9.0.58-1ubuntu0.2+esm4 Available with Ubuntu Pro Ubuntu 20.04 LTS libtomcat9-embed-java 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro libtomcat9-java 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro tomcat9 9.0.31-1ubuntu0.9+esm3 Available with Ubuntu Pro Ubuntu 18.04 LTS libtomcat9-embed-java 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro libtomcat9-java 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro tomcat9 9.0.16-3ubuntu0.18.04.2+esm8 Available with Ubuntu Pro After a standard system update you need to restart Tomcat to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8417-1 CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43512, CVE-2026-43513, CVE-2026-43515 Package Information: https://launchpad.net/ubuntu/+source/tomcat10/10.1.40-1ubuntu1.26.04.1 https://launchpad.net/ubuntu/+source/tomcat9/9.0.115-1ubuntu0.1 https://launchpad.net/ubuntu/+source/tomcat10/10.1.40-1ubuntu1.25.10.1 https://launchpad.net/ubuntu/+source/tomcat9/9.0.95-1ubuntu1.1 . Address multiple security concerns with Tomcat in Ubuntu 20.04 to 26.04 for safer usage. Update as advised.. Ubuntu Tomcat security issues. . Severity: Critical. LinuxSecurity.com Team
Ron Ben Yizhak discovered that the inetutils implementation of telnetd didn't sanitise the CREDENTIALS_DIRECTORY environment variable before passing it to the login binary. This could be exploited to bypass authentication and login as root. For the stable distribution (trixie), this problem has been fixed in. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6144-1
A flaw was found in Sympaâs web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4027-1
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for dbus-1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1591-1 Rating: important References: #1137832 Cross-References: CVE-2019-12749 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Server 12-LTSS SUSE Enterprise Storage 4 OpenStack Cloud Magnum Orchestration 7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for dbus-1 fixes the following issue: Security issue fixed: - CVE-2019-12749: Fixed an implementation flaw in DBUS_COOKIE_SHA1 which could have allowed local attackers to bypass authentication (bsc#1137832). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-1591=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-1591=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-1591=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-1591=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-1591=1 - SUSE Linux Enterprise Server12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-1591=1 - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2019-1591=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-1591=1 - OpenStack Cloud Magnum Orchestration 7: zypper in -t patch SUSE-OpenStack-Cloud-Magnum-Orchestration-7-2019-1591=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): dbus-1-debuginfo-32bit-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): dbus-1-debuginfo-32bit-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x x86_64): dbus-1-debuginfo-32bit-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-LTSS (ppc64le s390x x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 - SUSE Linux Enterprise Server 12-LTSS (s390x x86_64): libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - SUSEEnterprise Storage 4 (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debuginfo-32bit-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-32bit-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 libdbus-1-3-debuginfo-32bit-1.8.22-24.19.1 - OpenStack Cloud Magnum Orchestration 7 (x86_64): dbus-1-1.8.22-24.19.1 dbus-1-debuginfo-1.8.22-24.19.1 dbus-1-debugsource-1.8.22-24.19.1 dbus-1-x11-debuginfo-1.8.22-24.19.1 dbus-1-x11-debugsource-1.8.22-24.19.1 libdbus-1-3-1.8.22-24.19.1 libdbus-1-3-debuginfo-1.8.22-24.19.1 References: https://www.suse.com/security/cve/CVE-2019-12749.html https://bugzilla.suse.com/1137832 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.