The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:
[1:9.0.120-1] - Resolves: RHEL-192825 HTTP/2 request headers not validated (CVE-2026-41293) - Resolves: RHEL-192659 Improper Input Validation vulnerability due to incomplete fix (CVE-2026-32990) - Resolves: RHEL-219565 Security constraint bypass via improper URL encoding in rewrite valve (CVE-2026-59083) - Resolves: RHEL-219573 Insufficient documentation for EncryptInterceptor may lead to insecure configurations (CVE-2026-59084) - Resolves: RHEL-238189 tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication (CVE-2026-42498) - Resolves: RHEL-238247 tomcat: Improper Handling of Case Sensitivity in LockOutRealm (CVE-2026-43513) - Resolves: RHEL-238277 tomcat: Improper Authorization allows security bypass (CVE-2026-43515) - Resolves: RHEL-238302 tomcat: Authentication bypass via digest authentication (CVE-2026-43512) - Related: RHEL-183992 Remove tomcat clustering JAR from RPM builds [1:9.0.110-1] - Resolves: RHEL-148687 Update to 9....
![]()
http://oss.oracle.com/ol9/SRPMS-updates/tomcat-9.0.120-2.el9_8.src.rpm
tomcat-9.0.120-2.el9_8.noarch.rpm tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm tomcat-lib-9.0.120-2.el9_8.noarch.rpm tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm tomcat-webapps-9.0.120-2.el9_8.noarch.rpm
tomcat-9.0.120-2.el9_8.noarch.rpm tomcat-admin-webapps-9.0.120-2.el9_8.noarch.rpm tomcat-docs-webapp-9.0.120-2.el9_8.noarch.rpm tomcat-el-3.0-api-9.0.120-2.el9_8.noarch.rpm tomcat-jsp-2.3-api-9.0.120-2.el9_8.noarch.rpm tomcat-lib-9.0.120-2.el9_8.noarch.rpm tomcat-servlet-4.0-api-9.0.120-2.el9_8.noarch.rpm tomcat-webapps-9.0.120-2.el9_8.noarch.rpm
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Oracle Linux 9 Kernel Important Bug Fix Advisory ELSA-2026-68570 | 0 | 12.8 | 21-09-2026 |
| 2 | Oracle Linux 9 perl-Net-DNS Important TSIG Issue Advisory ELSA-2026-68786 | 0 | 16 | 21-09-2026 |
| 3 | Oracle Linux 9 Image Builder Important Update ELSA-2026-67138-0 | 0 | 12.86 | 21-09-2026 |
| 4 | Oracle Linux Tomcat Moderate Input Validation Bypass Fix ELSA-2026-68651 | 0 | 10.42 | 21-09-2026 |
| 5 | Oracle Linux 8 Tomcat Important Security Advisory ELSA-2026-68677 | 0 | 12.86 | 21-09-2026 |
| 6 | Oracle Linux 8 Kernel Important Security Update ELSA-2026-68531 | 0 | 12.86 | 21-09-2026 |
| 7 | Essential Oracle 8 libevent Updates for CVE-2026-63382 and ELSA-2026-67908 | 0 | 12.8 | 21-09-2026 |
| 8 | Oracle Linux 8 Python-lxml Important Security Issues ELSA-2026-67943 | 0 | 16.16 | 21-09-2026 |
| 9 | Oracle ELSA-2026-68676 - Important Bug Fix in .NET 10.0 Version | 0 | 14.63 | 21-09-2026 |
| 10 | Oracle 8 Perl-Net-DNS Important Unbounded Recursion Threat ELSA-2026-68787 | 0 | 17.36 | 21-09-2026 |