==========================================================================
Ubuntu Security Notice USN-8369-2
July 23, 2026

libapache-mod-jk regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

USN-8369-1 introduced a regression in mod_jk

Software Description:
- libapache-mod-jk: Apache 2 connector for the Tomcat Java servlet engine

Details:

USN-8369-1 fixed a vulnerability in mod_jk. It was discovered that for
Ubuntu 18.04 LTS, during the update preparation phase, a previous  fix for
CVE-2023-41081 was incorrectly dropped. This update  reintroduces the fix
for CVE-2023-41081.

We apologize for the inconvenience.

Original advisory details:

 It was discovered that Apache Tomcat Connectors used incorrect default
 permissions for shared memory on Unix-like systems. A local attacker could
 possibly use this issue to view or modify mod_jk configuration data in
 shared memory, resulting in sensitive information exposure or a denial of
 service.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  libapache2-mod-jk               1:1.2.41-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8369-2
  https://ubuntu.com/security/notices/USN-8369-1
  CVE-2023-41081, https://launchpad.net/bugs/2161580

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to