Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package tomcat for openSUSE:Factory checked 
in at 2026-09-28 10:42:36
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/tomcat (Old)
 and      /work/SRC/openSUSE:Factory/.tomcat.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "tomcat"

Mon Sep 28 10:42:36 2026 rev:132 rq:1380681 version:9.0.122

Changes:
--------
--- /work/SRC/openSUSE:Factory/tomcat/tomcat.changes    2026-09-11 
18:07:33.516471781 +0200
+++ /work/SRC/openSUSE:Factory/.tomcat.new.383539/tomcat.changes        
2026-09-28 10:42:46.678716517 +0200
@@ -1,0 +2,143 @@
+Fri Sep 25 12:07:34 UTC 2026 - mbussolotto <[email protected]>
+
+- Update to Tomcat 9.0.122
+  * Fixed CVEs:
+    + CVE-2026-87022: Improper handling of length parameter allows WebSocket
+      message smuggling when per-message-deflate is used. (bsc#1282581)
+    + CVE-2026-86350: Inconsistent interpretation of HTTP/2 requests caused by
+      a regression in fix for CVE-2026-41293 can trigger request header mix-
+      up.
+    + CVE-2026-86248: CLIENT_CERT authentication does not fail as expected for
+      some scenarios when OCSP soft fail is disabled. (bsc#1282620)
+    + CVE-2026-79677: Due to a concurrency bug, an attacker could trigger a
+      denial of service as a result of lost time outs for asynchronous
+      WebSocket writes. (bsc#1282624)
+    + CVE-2026-78437: A malformed HTTP/2 request could potentially (depends on
+      timing) cause one request from another user to fail. (bsc#1282625)
+    + CVE-2026-78383: If the end user did not provide a request body, that
+      could pin an AJP processing thread leading to denial of service.
+      (bsc#1282626)
+    + CVE-2026-77791: A busy wait during sending of WebSocket close message
+      enabled a DoS attack. (bsc#1282627)
+    + CVE-2026-77762: A race condition allowed an attacker to inject trailer
+      fields into another HTTP/2 request. (bsc#1282599)
+    + CVE-2026-77756: Processing the transfer-encoding header for an HTTP/1.0
+      request may allow an attacker to cause one request from another user to
+      fail when Tomcat is located behind a reverse proxy. (bsc#1282628)
+    + CVE-2026-76183: Request paths were incorrectly parsed as endpoint
+      templates allowing the bypass of security constraints for WebSocket
+      endpoints. (bsc#1282629)
+    + CVE-2026-75973: When Jakarta Authentication was configured with
+      SimpleAuthConfigProvider as the default provider and multiple web
+      application used that provider, the realm for the first web application
+      to authenticate a request would be used for all web applications.
+      (bsc#1282630)
+    + CVE-2026-73581: Both the OpenSSL and OpenSSL-FFM TLS implementations
+      ignored CRLs when certificate used a keystore. (bsc#1282631)
+  * Catalina
+    + Fix: Improve the handling of AsyncContext.dispatch() when the Context
+      attribute dispatchersUseEncodedPaths is set to false since the
+      application has no control over the path used for the
+      AsyncContext.dispatch(). Prior to this fix, paths containing literal '?'
+      characters were truncated. (markt)
+    + Fix: Ensure that capture groups from a RewriteCond always reflect the
+      result of the current request. (markt)
+    + Fix: When a PersistentManager needs to reduce the number of active
+      sessions, swap out the least recently used eligible sessions first. Pull
+      request #1045 provided by sainadh777. (markt)
+    + Fix: Align web.xml logging output with the new Context attribute
+      urlPatternsProvidedInDecodedForm. (markt)
+    + Fix: Improve robustness of DIGEST authentication to system clock jumps.
+      (markt)
+    + Add: Support multiple protocol header values (treat as a single merged
+      header value) in the RemoteIpFilter and RemoteIpValve. (markt)
+    + Fix: potential concurrency issues when loading/saving sessions from/to a
+      session store. Custom Store implementations that do not extend StoreBase
+      must implement the new getSessionStoreLock() method of the Store
+      interface to ensure concurrency protection. The default method
+      implementation provided only provides the pre-fix functionality. (markt)
+    + Fix: Ensure that PersistentManager implementations that extend
+      PersistentManagerBase do not swap out sessions that are associated with
+      a request that is currently being processed. As a result, it is now a
+      requirement that the system property
+      org.apache.catalina.session.StandardSession.ACTIVITY_CHECK is set to
+      true (either explicitly or via STRICT_SERVLET_COMPLIANCE) if either
+      minIdleSwap or maxIdleSwap are configured. (markt)
+  * Coyote
+    + Fix: xreflection generated code stack overflow issue. (remm)
+    + Fix: Align xreflection better with IntrospectionUtils. (remm)
+    + Fix: In HTTP/2 after half closed (remote), any unexpected frame should
+      be a stream error. (remm)
+    + Fix: incorrect initial window size calculation when upgrading to HTTP/2.
+      (remm)
+    + Fix: Avoid HTTP/2 exceptions with invalid content-length values. (remm)
+    + Fix: Only try and load the native library from the CATALINA_HOME system
+      property when the property is set. (markt)
+    + Fix: max connections enforcement after an enpoint resume. (remm)
+    + Fix: Implement stricter ALPN matching for Connectors using FFM. (markt)
+    + Add: length validation for ALPN protocol names. (markt)
+    + Fix: Make FFM certificate verification more robust. (markt)
+    + Fix: Align FFM OCSP URL parsing with Tomcat Native and treat a parsing
+      failure as if no usable OCSP URLs were present. (markt)
+    + Fix: Make the processing of OCSP responses more robust. (markt)
+    + Fix: Stricter OCSP handling when soft-fail is disabled. (markt)
+    + Fix: Cleaner handling of AJP response headers which overflow the maximum
+      message size. (remm)
+    + Fix: Small per performance optimisation. Don't waste cycles swallowing
+      an AJP response body when the connection is going to be closed. (markt)
+    + Fix: OpenSSL support for CRLs when using OpenSSL trust with the server
+      key held in a Java key store. (markt)
+    + Fix: Reject HTTP/1.0 or earlier requests that send a transfer-encoding
+      header. (markt)
+    + Fix: Ensure per request HTTP/2 bad request marker is cleared when the
+      request is recycled. (markt)
+    + Fix: Additional clean-up after HTTP/2 stream reset to aid GC. (markt)
+    + Fix: Revert earlier refactoring of HTTP/2 header field validation that
+      moved it earlier since the refactoring made correct handling of invalid
+      headers more difficult. (markt)
+  * Jasper
+    + Fix: EL evaluation of some lambda expressions. (remm)
+  * WebSocket
+    + Fix: an exception when an automatic Pong response races with the closing
+      of the WebSocket session. (moritzfl)
+    + Fix: Harden the WebSocket client and use a SecureRandom when generating
+      the Sec-WebSocket-Key header. (markt)
+    + Fix: Improve robustness of client handshakes. (remm)
+    + Fix: Ensure that WebSocket write timeouts apply to the complete message
+      and are not lost if two writes have the same timeout. (markt)
+    + Fix: Reduce CPU usage while sending WebSocket close message. (markt)
+    + Fix: overly broad check that prevented request URIs containing literal {
+      and } characters from being mapped to WebSocket end points. (markt)
+    + Fix: handling of WebSocket messages with compressed payloads using per-
+      message-deflate that have one or more non-final blocks where the BFINAL
+      bit is set. (markt)
+    + Fix: handling of per-message-deflate context takeover when receiving
+      compressed WebSocket messages. (markt)
+  * Web applications
+    + Fix: Manager: Fix a potential concurrency issue when ordering sessions
+      prior to displaying a list of session. (markt)
+    + Docs: Wrap the RewriteRule regular expression syntax reference on narrow
+      displays. Pull request #1044 by sainadh777. (markt)
+  * Other
+    + Update: Easymock to 5.7.0. (markt)
+    + Update: bnd to 7.4.0. (markt)
+    + Update: Tomcat Native to 1.3.9. (markt)
+    + Add: Improvements to French translations. (remm)
+    + Add: Improvements to Japanese translations provided by tak7iji and
+      Ktamura.biz.80. (markt)
+  * Cluster
+    + Fix: Validate that the DeltaManager attribute sendAllSessionsSize is a
+      positive integer. Zero or negative values previously caused an infinite
+      loop or a NegativeArraySizeException during session state transfer. Pull
+      request #1042 provided by lihongyi87. (markt)
+    + Fix: Improve robustness of cloud membership providers if an error occurs
+      fetching members. (remm)
+  * jdbc-pool
+    + Fix: DataSourceProxy.getPooledConnection(String,String) now delegates to
+      getConnection(String,String) rather than getConnection(). (markt)
+    + Add: Log a warning if an attempt is made to obtain a connection with
+      credentials when alternateUsernameAllowed is set to false. (markt)
+    + Fix: Ensure StatementCache interceptor resets properties of cached
+      statements between uses. (mark)
+
+-------------------------------------------------------------------

Old:
----
  apache-tomcat-9.0.121-src.tar.gz
  apache-tomcat-9.0.121-src.tar.gz.asc

New:
----
  apache-tomcat-9.0.122-src.tar.gz
  apache-tomcat-9.0.122-src.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ tomcat.spec ++++++
--- /var/tmp/diff_new_pack.vl565Q/_old  2026-09-28 10:42:47.679758437 +0200
+++ /var/tmp/diff_new_pack.vl565Q/_new  2026-09-28 10:42:47.681758521 +0200
@@ -22,7 +22,7 @@
 %define elspec 3.0
 %define major_version 9
 %define minor_version 0
-%define micro_version 121
+%define micro_version 122
 %define packdname apache-tomcat-%{version}-src
 # FHS 2.3 compliant tree structure - http://www.pathname.com/fhs/2.3/
 %global basedir /srv/%{name}

++++++ _scmsync.obsinfo ++++++
--- /var/tmp/diff_new_pack.vl565Q/_old  2026-09-28 10:42:47.721760196 +0200
+++ /var/tmp/diff_new_pack.vl565Q/_new  2026-09-28 10:42:47.724760322 +0200
@@ -1,6 +1,6 @@
-mtime: 1788788233
-commit: b4b09d4dd5796fe9d32526075ad38c4432a79aa3b9e96a961396d150d020221c
+mtime: 1790338056
+commit: dc7eb9491a843194f1fc5014b49a612448944f9ac0b5d46d60f87b0c3615e76f
 url: https://src.opensuse.org/java-packages/tomcat
-revision: b4b09d4dd5796fe9d32526075ad38c4432a79aa3b9e96a961396d150d020221c
+revision: dc7eb9491a843194f1fc5014b49a612448944f9ac0b5d46d60f87b0c3615e76f
 projectscmsync: https://src.opensuse.org/java-packages/_ObsPrj
 

++++++ apache-tomcat-9.0.121-src.tar.gz -> apache-tomcat-9.0.122-src.tar.gz 
++++++
/work/SRC/openSUSE:Factory/tomcat/apache-tomcat-9.0.121-src.tar.gz 
/work/SRC/openSUSE:Factory/.tomcat.new.383539/apache-tomcat-9.0.122-src.tar.gz 
differ: char 13, line 1

++++++ build.specials.obscpio ++++++

++++++ build.specials.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/.gitignore new/.gitignore
--- old/.gitignore      1970-01-01 01:00:00.000000000 +0100
+++ new/.gitignore      2026-09-25 14:07:36.000000000 +0200
@@ -0,0 +1,5 @@
+.osc
+*.obscpio
+*.osc
+_build.*
+.pbuild

Reply via email to