Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package tomcat for openSUSE:Factory checked in at 2026-09-28 10:42:36 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/tomcat (Old) and /work/SRC/openSUSE:Factory/.tomcat.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "tomcat" Mon Sep 28 10:42:36 2026 rev:132 rq:1380681 version:9.0.122 Changes: -------- --- /work/SRC/openSUSE:Factory/tomcat/tomcat.changes 2026-09-11 18:07:33.516471781 +0200 +++ /work/SRC/openSUSE:Factory/.tomcat.new.383539/tomcat.changes 2026-09-28 10:42:46.678716517 +0200 @@ -1,0 +2,143 @@ +Fri Sep 25 12:07:34 UTC 2026 - mbussolotto <[email protected]> + +- Update to Tomcat 9.0.122 + * Fixed CVEs: + + CVE-2026-87022: Improper handling of length parameter allows WebSocket + message smuggling when per-message-deflate is used. (bsc#1282581) + + CVE-2026-86350: Inconsistent interpretation of HTTP/2 requests caused by + a regression in fix for CVE-2026-41293 can trigger request header mix- + up. + + CVE-2026-86248: CLIENT_CERT authentication does not fail as expected for + some scenarios when OCSP soft fail is disabled. (bsc#1282620) + + CVE-2026-79677: Due to a concurrency bug, an attacker could trigger a + denial of service as a result of lost time outs for asynchronous + WebSocket writes. (bsc#1282624) + + CVE-2026-78437: A malformed HTTP/2 request could potentially (depends on + timing) cause one request from another user to fail. (bsc#1282625) + + CVE-2026-78383: If the end user did not provide a request body, that + could pin an AJP processing thread leading to denial of service. + (bsc#1282626) + + CVE-2026-77791: A busy wait during sending of WebSocket close message + enabled a DoS attack. (bsc#1282627) + + CVE-2026-77762: A race condition allowed an attacker to inject trailer + fields into another HTTP/2 request. (bsc#1282599) + + CVE-2026-77756: Processing the transfer-encoding header for an HTTP/1.0 + request may allow an attacker to cause one request from another user to + fail when Tomcat is located behind a reverse proxy. (bsc#1282628) + + CVE-2026-76183: Request paths were incorrectly parsed as endpoint + templates allowing the bypass of security constraints for WebSocket + endpoints. (bsc#1282629) + + CVE-2026-75973: When Jakarta Authentication was configured with + SimpleAuthConfigProvider as the default provider and multiple web + application used that provider, the realm for the first web application + to authenticate a request would be used for all web applications. + (bsc#1282630) + + CVE-2026-73581: Both the OpenSSL and OpenSSL-FFM TLS implementations + ignored CRLs when certificate used a keystore. (bsc#1282631) + * Catalina + + Fix: Improve the handling of AsyncContext.dispatch() when the Context + attribute dispatchersUseEncodedPaths is set to false since the + application has no control over the path used for the + AsyncContext.dispatch(). Prior to this fix, paths containing literal '?' + characters were truncated. (markt) + + Fix: Ensure that capture groups from a RewriteCond always reflect the + result of the current request. (markt) + + Fix: When a PersistentManager needs to reduce the number of active + sessions, swap out the least recently used eligible sessions first. Pull + request #1045 provided by sainadh777. (markt) + + Fix: Align web.xml logging output with the new Context attribute + urlPatternsProvidedInDecodedForm. (markt) + + Fix: Improve robustness of DIGEST authentication to system clock jumps. + (markt) + + Add: Support multiple protocol header values (treat as a single merged + header value) in the RemoteIpFilter and RemoteIpValve. (markt) + + Fix: potential concurrency issues when loading/saving sessions from/to a + session store. Custom Store implementations that do not extend StoreBase + must implement the new getSessionStoreLock() method of the Store + interface to ensure concurrency protection. The default method + implementation provided only provides the pre-fix functionality. (markt) + + Fix: Ensure that PersistentManager implementations that extend + PersistentManagerBase do not swap out sessions that are associated with + a request that is currently being processed. As a result, it is now a + requirement that the system property + org.apache.catalina.session.StandardSession.ACTIVITY_CHECK is set to + true (either explicitly or via STRICT_SERVLET_COMPLIANCE) if either + minIdleSwap or maxIdleSwap are configured. (markt) + * Coyote + + Fix: xreflection generated code stack overflow issue. (remm) + + Fix: Align xreflection better with IntrospectionUtils. (remm) + + Fix: In HTTP/2 after half closed (remote), any unexpected frame should + be a stream error. (remm) + + Fix: incorrect initial window size calculation when upgrading to HTTP/2. + (remm) + + Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm) + + Fix: Only try and load the native library from the CATALINA_HOME system + property when the property is set. (markt) + + Fix: max connections enforcement after an enpoint resume. (remm) + + Fix: Implement stricter ALPN matching for Connectors using FFM. (markt) + + Add: length validation for ALPN protocol names. (markt) + + Fix: Make FFM certificate verification more robust. (markt) + + Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing + failure as if no usable OCSP URLs were present. (markt) + + Fix: Make the processing of OCSP responses more robust. (markt) + + Fix: Stricter OCSP handling when soft-fail is disabled. (markt) + + Fix: Cleaner handling of AJP response headers which overflow the maximum + message size. (remm) + + Fix: Small per performance optimisation. Don't waste cycles swallowing + an AJP response body when the connection is going to be closed. (markt) + + Fix: OpenSSL support for CRLs when using OpenSSL trust with the server + key held in a Java key store. (markt) + + Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding + header. (markt) + + Fix: Ensure per request HTTP/2 bad request marker is cleared when the + request is recycled. (markt) + + Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt) + + Fix: Revert earlier refactoring of HTTP/2 header field validation that + moved it earlier since the refactoring made correct handling of invalid + headers more difficult. (markt) + * Jasper + + Fix: EL evaluation of some lambda expressions. (remm) + * WebSocket + + Fix: an exception when an automatic Pong response races with the closing + of the WebSocket session. (moritzfl) + + Fix: Harden the WebSocket client and use a SecureRandom when generating + the Sec-WebSocket-Key header. (markt) + + Fix: Improve robustness of client handshakes. (remm) + + Fix: Ensure that WebSocket write timeouts apply to the complete message + and are not lost if two writes have the same timeout. (markt) + + Fix: Reduce CPU usage while sending WebSocket close message. (markt) + + Fix: overly broad check that prevented request URIs containing literal { + and } characters from being mapped to WebSocket end points. (markt) + + Fix: handling of WebSocket messages with compressed payloads using per- + message-deflate that have one or more non-final blocks where the BFINAL + bit is set. (markt) + + Fix: handling of per-message-deflate context takeover when receiving + compressed WebSocket messages. (markt) + * Web applications + + Fix: Manager: Fix a potential concurrency issue when ordering sessions + prior to displaying a list of session. (markt) + + Docs: Wrap the RewriteRule regular expression syntax reference on narrow + displays. Pull request #1044 by sainadh777. (markt) + * Other + + Update: Easymock to 5.7.0. (markt) + + Update: bnd to 7.4.0. (markt) + + Update: Tomcat Native to 1.3.9. (markt) + + Add: Improvements to French translations. (remm) + + Add: Improvements to Japanese translations provided by tak7iji and + Ktamura.biz.80. (markt) + * Cluster + + Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a + positive integer. Zero or negative values previously caused an infinite + loop or a NegativeArraySizeException during session state transfer. Pull + request #1042 provided by lihongyi87. (markt) + + Fix: Improve robustness of cloud membership providers if an error occurs + fetching members. (remm) + * jdbc-pool + + Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to + getConnection(String,String) rather than getConnection(). (markt) + + Add: Log a warning if an attempt is made to obtain a connection with + credentials when alternateUsernameAllowed is set to false. (markt) + + Fix: Ensure StatementCache interceptor resets properties of cached + statements between uses. (mark) + +------------------------------------------------------------------- Old: ---- apache-tomcat-9.0.121-src.tar.gz apache-tomcat-9.0.121-src.tar.gz.asc New: ---- apache-tomcat-9.0.122-src.tar.gz apache-tomcat-9.0.122-src.tar.gz.asc ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ tomcat.spec ++++++ --- /var/tmp/diff_new_pack.vl565Q/_old 2026-09-28 10:42:47.679758437 +0200 +++ /var/tmp/diff_new_pack.vl565Q/_new 2026-09-28 10:42:47.681758521 +0200 @@ -22,7 +22,7 @@ %define elspec 3.0 %define major_version 9 %define minor_version 0 -%define micro_version 121 +%define micro_version 122 %define packdname apache-tomcat-%{version}-src # FHS 2.3 compliant tree structure - http://www.pathname.com/fhs/2.3/ %global basedir /srv/%{name} ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.vl565Q/_old 2026-09-28 10:42:47.721760196 +0200 +++ /var/tmp/diff_new_pack.vl565Q/_new 2026-09-28 10:42:47.724760322 +0200 @@ -1,6 +1,6 @@ -mtime: 1788788233 -commit: b4b09d4dd5796fe9d32526075ad38c4432a79aa3b9e96a961396d150d020221c +mtime: 1790338056 +commit: dc7eb9491a843194f1fc5014b49a612448944f9ac0b5d46d60f87b0c3615e76f url: https://src.opensuse.org/java-packages/tomcat -revision: b4b09d4dd5796fe9d32526075ad38c4432a79aa3b9e96a961396d150d020221c +revision: dc7eb9491a843194f1fc5014b49a612448944f9ac0b5d46d60f87b0c3615e76f projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj ++++++ apache-tomcat-9.0.121-src.tar.gz -> apache-tomcat-9.0.122-src.tar.gz ++++++ /work/SRC/openSUSE:Factory/tomcat/apache-tomcat-9.0.121-src.tar.gz /work/SRC/openSUSE:Factory/.tomcat.new.383539/apache-tomcat-9.0.122-src.tar.gz differ: char 13, line 1 ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-09-25 14:07:36.000000000 +0200 @@ -0,0 +1,5 @@ +.osc +*.obscpio +*.osc +_build.* +.pbuild
