Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
MGASA-2026-0095 - Updated tomcat packages fix security vulnerabilities. MGASA-2026-0095 - Updated tomcat packages fix security vulnerabilities Publication date: 12 Apr 2026 URL: https://advisories.mageia.org/MGASA-2026-0095.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-24880, CVE-2026-25854, CVE-2026-29129, CVE-2026-29145, CVE-2026-29146, CVE-2026-32990, CVE-2026-34483, CVE-2026-34486, CVE-2026-34487, CVE-2026-34500 Description: Request smuggling via invalid chunk extension. (CVE-2026-24880) Occasionally open redirect. (CVE-2026-25854) TLS cipher order is not preserved. (CVE-2026-29129) OCSP checks sometimes soft-fail even when soft-fail is disabled. (CVE-2026-29145) EncryptInterceptor vulnerable to padding oracle attack by default. (CVE-2026-29146) Fix for CVE-2025-66614 is incomplete. (CVE-2026-32990) Incomplete escaping of JSON access logs. (CVE-2026-34483) Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor. (CVE-2026-34486) Cloud membership for clustering component exposed the Kubernetes bearer token. (CVE-2026-34487) OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled. (CVE-2026-34500) References: - https://bugs.mageia.org/show_bug.cgi?id=35341 - https://www.openwall.com/lists/oss-security/2026/04/09/20 - https://www.openwall.com/lists/oss-security/2026/04/09/21 - https://www.openwall.com/lists/oss-security/2026/04/09/22 - https://www.openwall.com/lists/oss-security/2026/04/09/23 - https://www.openwall.com/lists/oss-security/2026/04/09/24 - https://www.openwall.com/lists/oss-security/2026/04/09/25 - https://www.openwall.com/lists/oss-security/2026/04/09/26 - https://www.openwall.com/lists/oss-security/2026/04/09/27 - https://www.openwall.com/lists/oss-security/2026/04/09/28 - https://www.openwall.com/lists/oss-security/2026/04/09/29 - https://www.cve.org/CVERecord?id=CVE-2026-24880 - https://www.cve.org/CVERecord?id=CVE-2026-25854 - https://www.cve.org/CVERecord?id=CVE-2026-29129 -https://www.cve.org/CVERecord?id=CVE-2026-29145 - https://www.cve.org/CVERecord?id=CVE-2026-29146 - https://www.cve.org/CVERecord?id=CVE-2026-32990 - https://www.cve.org/CVERecord?id=CVE-2026-34483 - https://www.cve.org/CVERecord?id=CVE-2026-34486 - https://www.cve.org/CVERecord?id=CVE-2026-34487 - https://www.cve.org/CVERecord?id=CVE-2026-34500 SRPMS: - 9/core/tomcat-9.0.117-1.mga9 . Updated Tomcat packages in Mageia address security issues like request smuggling and padding oracle attacks.. Mageia Security Advisory, Tomcat Security Update, Request Smuggling Fix. . Severity: Important. LinuxSecurity.com Team
Two vulnerabilities were discovered in phpseclib, a PHP Secure Communications Library. CVE-2023-52892 Some characters in Subject Alternative Name fields in TLS certificates were incorrectly allowed to have a special meaning. Debian LTS Advisory DLA-4518-1
Juraj Somorovsky, Robert Merget and Nimrod Aviram discovered a padding oracle attack in OpenSSL. If an application encounters a fatal protocol error and then calls . Package : openssl Version : 1.0.1t-1+deb8u11 CVE ID : CVE-2019-1559 Juraj Somorovsky, Robert Merget and Nimrod Aviram discovered a padding oracle attack in OpenSSL. If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data. In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites. Also the application must call SSL_shutdown() twice even if a protocol error has occurred (applications should not do this but some do anyway). AEAD ciphersuites are not impacted. For Debian 8 "Jessie", this problem has been fixed in version 1.0.1t-1+deb8u11. We recommend that you upgrade your openssl packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : openssl Version : 1.0.1t-1+deb8u11 CVE ID : CVE-2019-1559 Juraj Somorovsky, Robert Merget . juraj, somorovsky, robert, merget, nimrod, aviram, padding, oracle, attack, openssl. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.