SUSE-SU-2026:23985-1: critical: Security update for libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10, tomcat11

SLE-SECURITY-UPDATES null at suse.de
Mon Oct 5 08:39:34 UTC 2026


# Security update for libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10,
tomcat11

Announcement ID: SUSE-SU-2026:23985-1  
Release Date: 2026-09-30T17:58:26Z  
Rating: critical  
References:

  * bsc#1282581
  * bsc#1282599
  * bsc#1282620
  * bsc#1282621
  * bsc#1282622
  * bsc#1282623
  * bsc#1282624
  * bsc#1282625
  * bsc#1282626
  * bsc#1282627
  * bsc#1282628
  * bsc#1282629
  * bsc#1282630
  * bsc#1282631
  * bsc#1282787
  * bsc#622430

  
Cross-References:

  * CVE-2026-73581
  * CVE-2026-75973
  * CVE-2026-76183
  * CVE-2026-77756
  * CVE-2026-77762
  * CVE-2026-77791
  * CVE-2026-78383
  * CVE-2026-78437
  * CVE-2026-79677
  * CVE-2026-86243
  * CVE-2026-86246
  * CVE-2026-86247
  * CVE-2026-86248
  * CVE-2026-86350
  * CVE-2026-87022

  
CVSS scores:

  * CVE-2026-73581 ( SUSE ):  6.9
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-73581 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-73581 ( NVD ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-75973 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-75973 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-75973 ( NVD ):  7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-76183 ( SUSE ):  9.3
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-76183 ( SUSE ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-76183 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-77756 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-77756 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-77756 ( NVD ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-77762 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-77762 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-77762 ( NVD ):  8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-77791 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-77791 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-77791 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-78383 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-78383 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-78383 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-78437 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-78437 ( SUSE ):  3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
  * CVE-2026-78437 ( NVD ):  7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  * CVE-2026-79677 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-79677 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-79677 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-86243 ( SUSE ):  8.7
    CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
  * CVE-2026-86243 ( SUSE ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-86243 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  * CVE-2026-86246 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-86246 ( SUSE ):  6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  * CVE-2026-86246 ( NVD ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-86247 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-86247 ( SUSE ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-86247 ( NVD ):  7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-86248 ( SUSE ):  9.1
    CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-86248 ( SUSE ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-86248 ( NVD ):  9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  * CVE-2026-86350 ( SUSE ):  9.2
    CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
  * CVE-2026-86350 ( SUSE ):  7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
  * CVE-2026-86350 ( NVD ):  9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  * CVE-2026-87022 ( SUSE ):  6.3
    CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
  * CVE-2026-87022 ( SUSE ):  5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
  * CVE-2026-87022 ( NVD ):  7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

  
Affected Products:

  * SUSE Linux Enterprise Server 16.0
  * SUSE Linux Enterprise Server for SAP applications 16.0

  
  
An update that solves 15 vulnerabilities and has one fix can now be installed.

## Description:

This update for libtcnative-1-0, libtcnative-2-0, tomcat, tomcat10, tomcat11
fixes the following issues:

Security issues fixed:

  * CVE-2026-73581: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when
    certificate uses a keystore (bsc#1282631).
  * CVE-2026-75973: improper authentication when Jakarta authentication is
    configured with `SimpleAuthConfigProvider` (bsc#1282630).
  * CVE-2026-76183: security constraints for any WebSocket endpoint can be
    bypassed (bsc#1282629).
  * CVE-2026-77756: inconsistent interpretation of HTTP requests allows an
    attacker to cause one request from another user to fail when Tomcat is
    located behind a reverse proxy (bsc#1282628).
  * CVE-2026-77762: Apache Tomcat: Stale HPACK emitter injects trailers
    (bsc#1282599).
  * CVE-2026-77791: uncontrolled resource consumption when sending WebSocket
    close message enabled a DoS attack (bsc#1282627).
  * CVE-2026-78383: allocation of resources without limits or throttling allows
    an unauthenticated AJP request to pin an AJP processing thread leading to
    denial of service (bsc#1282626).
  * CVE-2026-78437: incomplete cleanup allows a malformed request to potentially
    cause requests from another user to fail (bsc#1282625).
  * CVE-2026-79677: missing release of resource after effective lifetime and
    comparison using wrong factors allows for denial of service due to lost time
    outs for asynchronous WebSocket writes (bsc#1282624).
  * CVE-2026-86243: buffer overread during the TLS handshake permits a malicious
    user to trigger a DoS via a JVM crash (bsc#1282623).
  * CVE-2026-86246: insecure ALLOW_CLIENT_RENEGOTIATION,
    NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and ALLOW_NO_DHE_KEX
    options enabled by default (bsc#1282622).
  * CVE-2026-86247: race condition allows client certificate verification
    requirements to be down-graded for some configurations (bsc#1282621).
  * CVE-2026-86248: CLIENT_CERT authentication does not fail as expected for
    some scenarios when soft fail is disabled (bsc#1282620).
  * CVE-2026-86350: HTTP/2 requests can cause request header mix-ups and HTTP
    request smuggling (bsc#1282787).
  * CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with
    (bsc#1282581).

Non security issue fixed:

  * package libtcnative-1-0-devel houses link to libtcnative-1.so instead of
    package libtcnative-1-0 (bsc#622430).

Changes for libtcnative-1-0:

  * Update to 1.3.9
  * Code: Remove call to ERR_remove_thread_state() from Windows specific code to
    allow building with OpenSSL 4.0.x. ERR_remove_thread_state() is a no-op in
    OpenSSL 1.1+ and got removed in OpenSSL 4
  * Fix: Fix a potential crash when negotiating ALPN
  * If ALPN negotiation fails and failure is configured to use the last server
    protocol in the list, use it rather than the last protocol offered by the
    client
  * Fix: Add support for the extended range of options available from OpenSSL
    3.0.x. The options flag is now a 64-bit unsigned int (represented by a Java
    long) rather than a 32-bit unsigned int (represented by a Java int)
  * Code: Remove unused code
  * Ensure that per connection changes to certificate verification settings,
    e.g. to support client certificate authentication, do not modify the
    certificate verification settings for other connections
  * Fix: Fix a potential crash when configuring raw certificates
  * Fix: Avoid a potential crash with very long ALPN protocol names
  * Fix: Make the call to a CertificateVerifier more robust
  * Fix: Avoid a potential crash when processing OCSP URLs
  * Fix: Make the processing of OCSP responses more robust
  * Fix: Stricter OCSP handling when soft-fail is disabled
  * Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
  * Fix: Harden against the mis-use of Pool.destroy(long)
  * Code: The minimum supported OpenSSL version is now 3.0.x. OpenSSL 1.1.1
    support was accidentally broken in 1.3.8. As no bug reports were receive for
    that failure and since both Debian and Ubuntu versions that used OpenSSL
    1.1.1 have reached end of support, OpenSSL 1.1.1 is no longer supported
  * Update: OpenSSL 3.0.x is approaching end of support so the recommended
    version of OpenSSL (and the version that windows binaries will be built
    with) now follows the 3.5.x LTS branch
  * Fix: Switch to automatic configuration of DH parameters. Manual
    configuration attempts will be ignored
  * Code: Make setTmpECDHByCurveName() a NO-OP
  * Fix: Refactor extraction of ECDH curve name from the Certificate to avoid
    deprecated OpenSSL methods
  * Fix: Refactor the native implementation of SSL.getTime() to avoid the Y2038
    problem in SSL_SESSION_get_time() when running on a verion of OpenSSL that
    includes the new SSL_SESSION_get_time_ex() method

Changes for libtcnative-2-0:

  * Upgrade to version 2.0.16
  * Code: Remove call to ERR_remove_thread_state() from Windows specific code to
    allow building with OpenSSL 4.0.x ERR_remove_thread_state() is a no-op in
    OpenSSL 1.1+ and got removed in OpenSSL 4
  * Update: Remove support for Windows build on IA64 architecture (Itanium)
  * Update: Make x64 the default architecture for Windows build
  * Update: Make Windows 10 / 11 the default target version for Windows builds
  * Fix: Fix a potential crash when negotiating ALPN
  * Fix: If ALPN negotiation fails and failure is configured to use the last
    server protocol in the list, use it rather than the last protocol offered by
    the client
  * Fix: Add support for the extended range of options available from OpenSSL
    3.0.x. The options flag is now a 64-bit unsigned int (represented by a Java
    long) rather than a 32-bit unsigned int (represented by a Java int)
  * Code: Remove unused code
  * Fix: Ensure that per connection changes to certificate verification
    settings, e.g. to support client certificate authentication, do not modify
    the certificate verification settings for other connections
  * Fix: Fix a potential crash when configuring raw certificates
  * Fix: Avoid a potential crash with very long ALPN protocol names
  * Fix: Make the call to a CertificateVerifier more robust
  * Fix: Avoid a potential crash when processing OCSP URLs
  * Fix: Make the processing of OCSP responses more robust
  * Fix: Stricter OCSP handling when soft-fail is disabled
  * Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
  * Fix: Harden against the mis-use of Pool.destroy(long)

Changes for tomcat10:

  * Update to Tomcat 10.1.60
  * Fix: When a PersistentManager needs to reduce the number of active sessions,
    swap out the least recently used eligible sessions first. Pull request #1045
    provided by sainadh777. (markt)
  * Fix: Align web.xml logging output with the new Context attribute
    urlPatternsProvidedInDecodedForm. (markt)
  * Fix: Improve robustness of DIGEST authentication to system clock jumps.
    (markt)
  * Add: Support multiple protocol header values (treat as a single merged
    header value) in the RemoteIpFilter and RemoteIpValve. (markt)
  * Fix: potential concurrency issues when loading/saving sessions from/to a
    session store. Custom Store implementations that do not extend StoreBase
    must implement the new getSessionStoreLock() method of the Store interface
    to ensure concurrency protection. The default method implementation provided
    only provides the pre-fix functionality. (markt)
  * Fix: Ensure that PersistentManager implementations that extend
    PersistentManagerBase do not swap out sessions that are associated with a
    request that is currently being processed. This includes not swapping out a
    session unless the session was created when activity tracking was enabled.
    (markt)
  * Fix: Ensure namespace attributes are XML escaped in WebDAV responses.
  * Fix: Resolve null or missing rewrite substitutions as an empty string, to
    align with the mod_rewrite behavior. (remm)
  * Add: a best efforts protection in the CrawlerSessionManagerValve against
    crawlers being associated with an authenticated session. (markt)
  * Fix: Clarify the meaning of various RewriteValve server variables and
    explicitly use the canonical context path for the CONTEXT_PATH server
    variable. (markt)
  * Fix: storeconfig not saving the path when a context is saved in server.xml.
    (remm)
  * Fix: WAR URLConnection should propagate use of caching. (remm)
  * Fix: Ensure resources are evicted from the static resource cache in the
    correct order. (markt)
  * Fix: When Jakarta Authentication is configured for a web application, cache
    the ServerAuthConfig in the Authenticator valve. This ensures web
    application specific settings are cached on a per web application basis.
  * Fix: 70203: Fix RegistrationListener notifications in Jakarta Authentication
    implementation. (markt)
  * Fix: Handle CGI scripts that write excessively to stdout after setting an
    HTTP error status code. (schultz)
  * Fix: Require the request to the login action during FORM authentication to
    be made using HTTP POST. (markt)
  * Fix: 70208: Make URL encoding more robust. Based on pull request #1065 by
    Chenjp. (markt)
  * Coyote
  * Fix: xreflection generated code stack overflow issue. (remm)
  * Fix: Align xreflection better with IntrospectionUtils. (remm)
  * Fix: In HTTP/2 after half closed (remote), any unexpected frame should be a
    stream error. (remm)
  * Fix: incorrect initial window size calculation when upgrading to HTTP/2.
    (remm)
  * Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
  * Fix: Only try and load the native library from the CATALINA_HOME system
    property when the property is set. (markt)
  * Fix: max connections enforcement after an enpoint resume. (remm)
  * Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
  * Add: length validation for ALPN protocol names. (markt)
  * Fix: Make FFM certificate verification more robust. (markt)
  * Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing
    failure as if no usable OCSP URLs were present. (markt)
  * Fix: Make the processing of OCSP responses more robust. (markt)
  * Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
  * Fix: Cleaner handling of AJP response headers which overflow the maximum
    message size. (remm)
  * Fix: Small per performance optimisation. Don't waste cycles swallowing an
    AJP response body when the connection is going to be closed. (markt)
  * Fix: OpenSSL support for CRLs when using OpenSSL trust with the server key
    held in a Java key store. (markt)
  * Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding
    header. (markt)
  * Fix: Ensure per request HTTP/2 bad request marker is cleared when the
    request is recycled. (markt)
  * Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
  * Fix: Revert earlier refactoring of HTTP/2 header field validation that moved
    it earlier since the refactoring made correct handling of invalid headers
    more difficult. (markt)
  * Fix: EL evaluation of some lambda expressions. (remm)
  * WebSocket
  * Fix: an exception when an automatic Pong response races with the closing of
    the WebSocket session. (moritzfl)
  * Fix: Harden the WebSocket client and use a SecureRandom when generating the
    Sec-WebSocket-Key header. (markt)
  * Fix: Improve robustness of client handshakes. (remm)
  * Fix: Ensure that WebSocket write timeouts apply to the complete message and
    are not lost if two writes have the same timeout. (markt)
  * Fix: Reduce CPU usage while sending WebSocket close message. (markt)
  * Fix: overly broad check that prevented request URIs containing literal { and
    } characters from being mapped to WebSocket end points. (markt)
  * Fix: handling of WebSocket messages with compressed payloads using per-
    message-deflate that have one or more non-final blocks where the BFINAL bit
    is set. (markt)
  * Fix: handling of per-message-deflate context takeover when receiving
    compressed WebSocket messages. (markt)
  * Web applications
  * Fix: Manager: Fix a potential concurrency issue when ordering sessions prior
    to displaying a list of session. (markt)
  * Docs: Wrap the RewriteRule regular expression syntax reference on narrow
    displays. Pull request #1044 by sainadh777. (markt)
  * Other
  * Update: Easymock to 5.7.0. (markt)
  * Update: bnd to 7.4.0. (markt)
  * Update: Tomcat Native to 2.0.16. (markt)
  * Add: Improvements to French translations. (remm)
  * Add: Improvements to Japanese translations provided by tak7iji and
    Ktamura.biz.80. (markt)
  * Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a
    positive integer. Zero or negative values previously caused an infinite loop
    or a NegativeArraySizeException during session state transfer. Pull request
    #1042 provided by lihongyi87. (markt)
  * Fix: Improve robustness of cloud membership providers if an error occurs
    fetching members. (remm)
  * jdbc-pool
  * Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to
    getConnection(String,String) rather than getConnection(). (markt)
  * Add: Log a warning if an attempt is made to obtain a connection with
    credentials when alternateUsernameAllowed is set to false. (markt)
  * Fix: Ensure StatementCache interceptor resets properties of cached
    statements between uses. (mark)

Changes for tomcat11:

  * Update to Tomcat 11.0.26
  * Fix: Improve the handling of AsyncContext.dispatch() when the Context
    attribute dispatchersUseEncodedPaths is set to false since the application
    has no control over the path used for the AsyncContext.dispatch(). Prior to
    this fix, paths containing literal '?' characters were truncated. (markt)
  * Fix: Ensure that capture groups from a RewriteCond always reflect the result
    of the current request. (markt)
  * Fix: When a PersistentManager needs to reduce the number of active sessions,
    swap out the least recently used eligible sessions first. Pull request #1045
    provided by sainadh777. (markt)
  * Fix: Align web.xml logging output with the new Context attribute
    urlPatternsProvidedInDecodedForm. (markt)
  * Fix: Improve robustness of DIGEST authentication to system clock jumps.
    (markt)
  * Add: Support multiple protocol header values (treat as a single merged
    header value) in the RemoteIpFilter and RemoteIpValve. (markt)
  * Fix: potential concurrency issues when loading/saving sessions from/to a
    session store. Custom Store implementations that do not extend StoreBase
    must implement the new getSessionStoreLock() method of the Store interface
    to ensure concurrency protection. The default method implementation provided
    only provides the pre-fix functionality. (markt)
  * Fix: Ensure that PersistentManager implementations that extend
    PersistentManagerBase do not swap out sessions that are associated with a
    request that is currently being processed. This includes not swapping out a
    session unless the session was created when activity tracking was enabled.
    (markt)
  * Fix: Ensure namespace attributes are XML escaped in WebDAV responses.
  * Fix: Resolve null or missing rewrite substitutions as an empty string, to
    align with the mod_rewrite behavior. (remm)
  * Add: a best efforts protection in the CrawlerSessionManagerValve against
    crawlers being associated with an authenticated session. (markt)
  * Fix: Clarify the meaning of various RewriteValve server variables and
    explicitly use the canonical context path for the CONTEXT_PATH server
    variable. (markt)
  * Fix: storeconfig not saving the path when a context is saved in server.xml.
    (remm)
  * Fix: WAR URLConnection should propagate use of caching. (remm)
  * Fix: Ensure resources are evicted from the static resource cache in the
    correct order. (markt)
  * Fix: When Jakarta Authentication is configured for a web application, cache
    the ServerAuthConfig in the Authenticator valve. This ensures web
    application specific settings are cached on a per web application basis.
  * Fix: 70203: Fix RegistrationListener notifications in Jakarta Authentication
    implementation. (markt)
  * Fix: Handle CGI scripts that write excessively to stdout after setting an
    HTTP error status code. (schultz)
  * Fix: Require the request to the login action during FORM authentication to
    be made using HTTP POST. (markt)
  * Fix: 70208: Make URL encoding more robust. Based on pull request #1065 by
    Chenjp. (markt)
  * Coyote
  * Fix: parsing of client certificates that specify more than one OCSP
    responder for configurations that use OpenSSL-FFM. (markt)
  * Fix: xreflection generated code stack overflow issue. (remm)
  * Fix: Align xreflection better with IntrospectionUtils. (remm)
  * Fix: In HTTP/2 after half closed (remote), any unexpected frame should be a
    stream error. (remm)
  * Fix: incorrect initial window size calculation when upgrading to HTTP/2.
    (remm)
  * Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
  * Fix: Only try and load the native library from the CATALINA_HOME system
    property when the property is set. (markt)
  * Fix: max connections enforcement after an enpoint resume. (remm)
  * Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
  * Add: length validation for ALPN protocol names. (markt)
  * Fix: Make FFM certificate verification more robust. (markt)
  * Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing
    failure as if no usable OCSP URLs were present. (markt)
  * Fix: Make the processing of OCSP responses more robust. (markt)
  * Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
  * Fix: Cleaner handling of AJP response headers which overflow the maximum
    message size. (remm)
  * Fix: Small per performance optimisation. Don't waste cycles swallowing an
    AJP response body when the connection is going to be closed. (markt)
  * Fix: OpenSSL support for CRLs when using OpenSSL trust with the server key
    held in a Java key store. (markt)
  * Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding
    header. (markt)
  * Fix: Ensure per request HTTP/2 bad request marker is cleared when the
    request is recycled. (markt)
  * Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
  * Fix: Revert earlier refactoring of HTTP/2 header field validation that moved
    it earlier since the refactoring made correct handling of invalid headers
    more difficult. (markt)
  * Fix: EL evaluation of some lambda expressions. (remm)
  * WebSocket
  * Fix: an exception when an automatic Pong response races with the closing of
    the WebSocket session. (moritzfl)
  * Fix: Harden the WebSocket client and use a SecureRandom when generating the
    Sec-WebSocket-Key header. (markt)
  * Fix: Improve robustness of client handshakes. (remm)
  * Fix: Ensure that WebSocket write timeouts apply to the complete message and
    are not lost if two writes have the same timeout. (markt)
  * Fix: Reduce CPU usage while sending WebSocket close message. (markt)
  * Fix: overly broad check that prevented request URIs containing literal { and
    } characters from being mapped to WebSocket end points. (markt)
  * Fix: handling of WebSocket messages with compressed payloads using per-
    message-deflate that have one or more non-final blocks where the BFINAL bit
    is set. (markt)
  * Fix: handling of per-message-deflate context takeover when receiving
    compressed WebSocket messages. (markt)
  * Web applications
  * Fix: Manager: Fix a potential concurrency issue when ordering sessions prior
    to displaying a list of session. (markt)
  * Docs: Wrap the RewriteRule regular expression syntax reference on narrow
    displays. Pull request #1044 by sainadh777. (markt)
  * Other
  * Update: Easymock to 5.7.0. (markt)
  * Update: bnd to 7.4.0. (markt)
  * Update: Tomcat Native to 2.0.16. (markt)
  * Add: Improvements to French translations. (remm)
  * Add: Improvements to Japanese translations provided by tak7iji and
    Ktamura.biz.80. (markt)
  * Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a
    positive integer. Zero or negative values previously caused an infinite loop
    or a NegativeArraySizeException during session state transfer. Pull request
    #1042 provided by lihongyi87. (markt)
  * Fix: Improve robustness of cloud membership providers if an error occurs
    fetching members. (remm)
  * jdbc-pool
  * Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to
    getConnection(String,String) rather than getConnection(). (markt)
  * Add: Log a warning if an attempt is made to obtain a connection with
    credentials when alternateUsernameAllowed is set to false. (markt)
  * Fix: Ensure StatementCache interceptor resets properties of cached
    statements between uses. (mark)

Changes for tomcat:

  * Update to Tomcat 9.0.122
  * Fix: Improve the handling of AsyncContext.dispatch() when the Context
    attribute dispatchersUseEncodedPaths is set to false since the application
    has no control over the path used for the AsyncContext.dispatch(). Prior to
    this fix, paths containing literal '?' characters were truncated. (markt)
  * Fix: Ensure that capture groups from a RewriteCond always reflect the result
    of the current request. (markt)
  * Fix: When a PersistentManager needs to reduce the number of active sessions,
    swap out the least recently used eligible sessions first. Pull request #1045
    provided by sainadh777. (markt)
  * Fix: Align web.xml logging output with the new Context attribute
    urlPatternsProvidedInDecodedForm. (markt)
  * Fix: Improve robustness of DIGEST authentication to system clock jumps.
    (markt)
  * Add: Support multiple protocol header values (treat as a single merged
    header value) in the RemoteIpFilter and RemoteIpValve. (markt)
  * Fix: potential concurrency issues when loading/saving sessions from/to a
    session store. Custom Store implementations that do not extend StoreBase
    must implement the new getSessionStoreLock() method of the Store interface
    to ensure concurrency protection. The default method implementation provided
    only provides the pre-fix functionality. (markt)
  * Fix: Ensure that PersistentManager implementations that extend
    PersistentManagerBase do not swap out sessions that are associated with a
    request that is currently being processed. As a result, it is now a
    requirement that the system property
    org.apache.catalina.session.StandardSession.ACTIVITY_CHECK is set to true
    (either explicitly or via STRICT_SERVLET_COMPLIANCE) if either minIdleSwap
    or maxIdleSwap are configured. (markt)
  * Coyote
  * Fix: xreflection generated code stack overflow issue. (remm)
  * Fix: Align xreflection better with IntrospectionUtils. (remm)
  * Fix: In HTTP/2 after half closed (remote), any unexpected frame should be a
    stream error. (remm)
  * Fix: incorrect initial window size calculation when upgrading to HTTP/2.
    (remm)
  * Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
  * Fix: Only try and load the native library from the CATALINA_HOME system
    property when the property is set. (markt)
  * Fix: max connections enforcement after an enpoint resume. (remm)
  * Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
  * Add: length validation for ALPN protocol names. (markt)
  * Fix: Make FFM certificate verification more robust. (markt)
  * Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing
    failure as if no usable OCSP URLs were present. (markt)
  * Fix: Make the processing of OCSP responses more robust. (markt)
  * Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
  * Fix: Cleaner handling of AJP response headers which overflow the maximum
    message size. (remm)
  * Fix: Small per performance optimisation. Don't waste cycles swallowing an
    AJP response body when the connection is going to be closed. (markt)
  * Fix: OpenSSL support for CRLs when using OpenSSL trust with the server key
    held in a Java key store. (markt)
  * Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding
    header. (markt)
  * Fix: Ensure per request HTTP/2 bad request marker is cleared when the
    request is recycled. (markt)
  * Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
  * Fix: Revert earlier refactoring of HTTP/2 header field validation that moved
    it earlier since the refactoring made correct handling of invalid headers
    more difficult. (markt)
  * Fix: EL evaluation of some lambda expressions. (remm)
  * WebSocket
  * Fix: an exception when an automatic Pong response races with the closing of
    the WebSocket session. (moritzfl)
  * Fix: Harden the WebSocket client and use a SecureRandom when generating the
    Sec-WebSocket-Key header. (markt)
  * Fix: Improve robustness of client handshakes. (remm)
  * Fix: Ensure that WebSocket write timeouts apply to the complete message and
    are not lost if two writes have the same timeout. (markt)
  * Fix: Reduce CPU usage while sending WebSocket close message. (markt)
  * Fix: overly broad check that prevented request URIs containing literal { and
    } characters from being mapped to WebSocket end points. (markt)
  * Fix: handling of WebSocket messages with compressed payloads using per-
    message-deflate that have one or more non-final blocks where the BFINAL bit
    is set. (markt)
  * Fix: handling of per-message-deflate context takeover when receiving
    compressed WebSocket messages. (markt)
  * Web applications
  * Fix: Manager: Fix a potential concurrency issue when ordering sessions prior
    to displaying a list of session. (markt)
  * Docs: Wrap the RewriteRule regular expression syntax reference on narrow
    displays. Pull request #1044 by sainadh777. (markt)
  * Other
  * Update: Easymock to 5.7.0. (markt)
  * Update: bnd to 7.4.0. (markt)
  * Update: Tomcat Native to 1.3.9. (markt)
  * Add: Improvements to French translations. (remm)
  * Add: Improvements to Japanese translations provided by tak7iji and
    Ktamura.biz.80. (markt)
  * Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a
    positive integer. Zero or negative values previously caused an infinite loop
    or a NegativeArraySizeException during session state transfer. Pull request
    #1042 provided by lihongyi87. (markt)
  * Fix: Improve robustness of cloud membership providers if an error occurs
    fetching members. (remm)
  * jdbc-pool
  * Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to
    getConnection(String,String) rather than getConnection(). (markt)
  * Add: Log a warning if an attempt is made to obtain a connection with
    credentials when alternateUsernameAllowed is set to false. (markt)
  * Fix: Ensure StatementCache interceptor resets properties of cached
    statements between uses. (mark)

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".  
Alternatively you can run the command listed for your product:

  * SUSE Linux Enterprise Server for SAP applications 16.0  
    zypper in -t patch SUSE-SLES-16.0-1795

  * SUSE Linux Enterprise Server 16.0  
    zypper in -t patch SUSE-SLES-16.0-1795

## Package List:

  * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
    * libtcnative-2-0-debugsource-2.0.16-160000.1.1
    * libtcnative-1-0-1.3.9-160000.1.1
    * libtcnative-2-0-2.0.16-160000.1.1
    * libtcnative-1-0-debugsource-1.3.9-160000.1.1
    * libtcnative-2-0-debuginfo-2.0.16-160000.1.1
    * libtcnative-1-0-debuginfo-1.3.9-160000.1.1
  * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch)
    * tomcat-javadoc-9.0.122-160000.1.1
    * tomcat10-admin-webapps-10.1.60-160000.1.1
    * tomcat-embed-9.0.122-160000.1.1
    * tomcat10-doc-10.1.60-160000.1.1
    * tomcat11-jsvc-11.0.26-160000.1.1
    * tomcat11-doc-11.0.26-160000.1.1
    * tomcat10-docs-webapp-10.1.60-160000.1.1
    * tomcat10-lib-10.1.60-160000.1.1
    * tomcat10-servlet-6_0-api-10.1.60-160000.1.1
    * tomcat-servlet-4_0-api-9.0.122-160000.1.1
    * tomcat-9.0.122-160000.1.1
    * tomcat-jsp-2_3-api-9.0.122-160000.1.1
    * tomcat11-admin-webapps-11.0.26-160000.1.1
    * tomcat11-embed-11.0.26-160000.1.1
    * tomcat11-jsp-4_0-api-11.0.26-160000.1.1
    * tomcat11-el-6_0-api-11.0.26-160000.1.1
    * tomcat11-webapps-11.0.26-160000.1.1
    * tomcat-docs-webapp-9.0.122-160000.1.1
    * tomcat-admin-webapps-9.0.122-160000.1.1
    * tomcat-webapps-9.0.122-160000.1.1
    * tomcat-el-3_0-api-9.0.122-160000.1.1
    * tomcat10-jsvc-10.1.60-160000.1.1
    * tomcat-jsvc-9.0.122-160000.1.1
    * tomcat10-el-5_0-api-10.1.60-160000.1.1
    * tomcat10-webapps-10.1.60-160000.1.1
    * tomcat10-10.1.60-160000.1.1
    * tomcat-lib-9.0.122-160000.1.1
    * tomcat11-lib-11.0.26-160000.1.1
    * tomcat11-servlet-6_1-api-11.0.26-160000.1.1
    * tomcat10-embed-10.1.60-160000.1.1
    * tomcat10-jsp-3_1-api-10.1.60-160000.1.1
    * tomcat11-docs-webapp-11.0.26-160000.1.1
    * tomcat11-11.0.26-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
    * libtcnative-2-0-debugsource-2.0.16-160000.1.1
    * libtcnative-1-0-1.3.9-160000.1.1
    * libtcnative-2-0-2.0.16-160000.1.1
    * libtcnative-1-0-debugsource-1.3.9-160000.1.1
    * libtcnative-2-0-debuginfo-2.0.16-160000.1.1
    * libtcnative-1-0-debuginfo-1.3.9-160000.1.1
  * SUSE Linux Enterprise Server 16.0 (noarch)
    * tomcat-javadoc-9.0.122-160000.1.1
    * tomcat10-admin-webapps-10.1.60-160000.1.1
    * tomcat-embed-9.0.122-160000.1.1
    * tomcat10-doc-10.1.60-160000.1.1
    * tomcat11-jsvc-11.0.26-160000.1.1
    * tomcat11-doc-11.0.26-160000.1.1
    * tomcat10-docs-webapp-10.1.60-160000.1.1
    * tomcat10-lib-10.1.60-160000.1.1
    * tomcat10-servlet-6_0-api-10.1.60-160000.1.1
    * tomcat-servlet-4_0-api-9.0.122-160000.1.1
    * tomcat-9.0.122-160000.1.1
    * tomcat-jsp-2_3-api-9.0.122-160000.1.1
    * tomcat11-admin-webapps-11.0.26-160000.1.1
    * tomcat11-embed-11.0.26-160000.1.1
    * tomcat11-jsp-4_0-api-11.0.26-160000.1.1
    * tomcat11-el-6_0-api-11.0.26-160000.1.1
    * tomcat11-webapps-11.0.26-160000.1.1
    * tomcat-docs-webapp-9.0.122-160000.1.1
    * tomcat-admin-webapps-9.0.122-160000.1.1
    * tomcat-webapps-9.0.122-160000.1.1
    * tomcat-el-3_0-api-9.0.122-160000.1.1
    * tomcat10-jsvc-10.1.60-160000.1.1
    * tomcat-jsvc-9.0.122-160000.1.1
    * tomcat10-el-5_0-api-10.1.60-160000.1.1
    * tomcat10-webapps-10.1.60-160000.1.1
    * tomcat10-10.1.60-160000.1.1
    * tomcat-lib-9.0.122-160000.1.1
    * tomcat11-lib-11.0.26-160000.1.1
    * tomcat11-servlet-6_1-api-11.0.26-160000.1.1
    * tomcat10-embed-10.1.60-160000.1.1
    * tomcat10-jsp-3_1-api-10.1.60-160000.1.1
    * tomcat11-docs-webapp-11.0.26-160000.1.1
    * tomcat11-11.0.26-160000.1.1

## References:

  * https://www.suse.com/security/cve/CVE-2026-73581.html
  * https://www.suse.com/security/cve/CVE-2026-75973.html
  * https://www.suse.com/security/cve/CVE-2026-76183.html
  * https://www.suse.com/security/cve/CVE-2026-77756.html
  * https://www.suse.com/security/cve/CVE-2026-77762.html
  * https://www.suse.com/security/cve/CVE-2026-77791.html
  * https://www.suse.com/security/cve/CVE-2026-78383.html
  * https://www.suse.com/security/cve/CVE-2026-78437.html
  * https://www.suse.com/security/cve/CVE-2026-79677.html
  * https://www.suse.com/security/cve/CVE-2026-86243.html
  * https://www.suse.com/security/cve/CVE-2026-86246.html
  * https://www.suse.com/security/cve/CVE-2026-86247.html
  * https://www.suse.com/security/cve/CVE-2026-86248.html
  * https://www.suse.com/security/cve/CVE-2026-86350.html
  * https://www.suse.com/security/cve/CVE-2026-87022.html
  * https://bugzilla.suse.com/show_bug.cgi?id=1282581
  * https://bugzilla.suse.com/show_bug.cgi?id=1282599
  * https://bugzilla.suse.com/show_bug.cgi?id=1282620
  * https://bugzilla.suse.com/show_bug.cgi?id=1282621
  * https://bugzilla.suse.com/show_bug.cgi?id=1282622
  * https://bugzilla.suse.com/show_bug.cgi?id=1282623
  * https://bugzilla.suse.com/show_bug.cgi?id=1282624
  * https://bugzilla.suse.com/show_bug.cgi?id=1282625
  * https://bugzilla.suse.com/show_bug.cgi?id=1282626
  * https://bugzilla.suse.com/show_bug.cgi?id=1282627
  * https://bugzilla.suse.com/show_bug.cgi?id=1282628
  * https://bugzilla.suse.com/show_bug.cgi?id=1282629
  * https://bugzilla.suse.com/show_bug.cgi?id=1282630
  * https://bugzilla.suse.com/show_bug.cgi?id=1282631
  * https://bugzilla.suse.com/show_bug.cgi?id=1282787
  * https://bugzilla.suse.com/show_bug.cgi?id=622430

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.suse.com/pipermail/sle-security-updates/attachments/20261005/f2427487/attachment.htm>


More information about the sle-security-updates mailing list