CVE-2022-25762 Score 8.6

Bug #1976335 reported by Hans Dampf
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
tomcat9 (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Hi All,

i have not found anything about this security bug on this bug tracker. Please fix this asap

thank you

More Details

https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.21

https://nvd.nist.gov/vuln/detail/CVE-2022-25762

If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.

CVE References

information type: Private Security → Public Security
Changed in tomcat9 (Ubuntu):
status: New → Confirmed
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Hello Hans, the Ubuntu security team doesn't track security issues in Launchpad; you can check the status in:

https://ubuntu.com/security/cve-2022-25762

tomcat9 is in universe, so it's community supported; there's currently a handful of issues still open in the 18.04 LTS version:

https://ubuntu.com/security/cves?q=&package=tomcat9&priority=&version=bionic&status=

If you're in a position to be able to address this issue, it'd be nice if you could grab as many of the other open issues as possible.

Thanks

Revision history for this message
Hans Dampf (tomcat668) wrote :

Hi Arnold,

thanks for your answer.

i am interested, but i have no idea how package maintainer works.
is it time to get involved here?

Revision history for this message
Seth Arnold (seth-arnold) wrote :

Hello Hans, the general outline of the update preparation is sketched out on this wiki page https://wiki.ubuntu.com/SecurityTeam/UpdatePreparation -- it's not exhaustive, but it's a good start.

Thanks

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.