Back Linuxsecurity openSUSE tomcat11 Important DoS Exploit Issues Fixed 2026-4114
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
This update for tomcat11 fixes the following issues:
* CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint
* CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for
Unix Domain Sockets (bsc#1276894).
* CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI
validation - fix incomplete (bsc#1276895).
* CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST
authentication (bsc#1276896).
* CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule
and may bypass access control (bsc#1276897).
* CVE-2026-66299: memory exhaustion via maliciously slow clients due to the
WebSocket chat example providing an unbounded buffer for undelivered
messages (bsc#1273150).
* CVE-2026-66422: Apache Tomcat: Servlet role references can bypass
declarative role constraints (bsc#1276898).
* CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may...
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4114=1
zypper in -t patch SUSE-2026-4114=1
* Web and Scripting Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4114=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4114=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* tomcat11-lib-11.0.25-150600.13.33.2
* tomcat11-admin-webapps-11.0.25-150600.13.33.2
* tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2
* tomcat11-el-6_0-api-11.0.25-150600.13.33.2
* tomcat11-webapps-11.0.25-150600.13.33.2
* tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2
* tomcat11-11.0.25-150600.13.33.2
* openSUSE Leap 15.6 (noarch)
* tomcat11-lib-11.0.25-150600.13.33.2
* tomcat11-admin-webapps-11.0.25-150600.13.33.2
* tomcat11-embed-11.0.25-150600.13.33.2
* tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2
* tomcat11-el-6_0-api-11.0.25-150600.13.33.2
* tomcat11-jsvc-11.0.25-150600.13.33.2
* tomcat11-docs-webapp-11.0.25-150600.13.33.2
* tomcat11-webapps-11.0.25-150600.13.33.2
* tomcat11-doc-11.0.25-150600.13.33.2
* tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2
* tomcat11-11.0.25-150600.13.33.2
* Web and Scripting Module 15-SP7 (noarch)
* tomcat11-lib-11.0.25-150600.13.33.2
* tomcat11-admin-webapps-11.0.25-150600.13.33.2
*
*
*
*
*
*
*
*
*
*
*
*
*
*
*
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
