[ALSA-2025:11332] Important: tomcat9 security update
Type:
security
Severity:
important
Release date:
2025-07-21
Description:
Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. Security Fix(es): * tomcat: Incomplete fix for CVE-2024-50379 - RCE due to TOCTOU issue in JSP compilation (CVE-2024-56337) * tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame (CVE-2025-31650) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch tomcat9-webapps-9.0.87-5.el10_0.1.noarch.rpm 0774750ce0e449d7727031660965614ec7302e7de102d2ba43c5fddc95efcbfa
noarch tomcat9-el-3.0-api-9.0.87-5.el10_0.1.noarch.rpm 377c26073eb55d55fc42c847c0a416b32efdc2f1778f796108526a5fffff57b0
noarch tomcat9-jsp-2.3-api-9.0.87-5.el10_0.1.noarch.rpm 4b8d7fe49010156d7b8b7e708b692d711407644829c8b9ef019277e0dcbda23c
noarch tomcat9-servlet-4.0-api-9.0.87-5.el10_0.1.noarch.rpm 5ca50f35c5fa597f1298d7c046d4ddc79454065fbc05a62c2da22f16384f22ee
noarch tomcat9-admin-webapps-9.0.87-5.el10_0.1.noarch.rpm 6939699e6a86c6f44122ba4c75a49c58e9f0fcc1c223365a5517320dcbee68fe
noarch tomcat9-lib-9.0.87-5.el10_0.1.noarch.rpm c3c6ba7e78adac81bef7ac58e223fcfe18a1374ff3fd22101676a7da00bc2be1
noarch tomcat9-docs-webapp-9.0.87-5.el10_0.1.noarch.rpm cadbc40cca0d725d472ed62d8335da3292b2dc058c732889ba0b92b462361092
noarch tomcat9-9.0.87-5.el10_0.1.noarch.rpm e6fcf1657945d58915566da5ae80e1811e6a8d96ae017d685c967838334fa9b4
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.