GSA-6329-1: Critical Tomcat 11 Security Update
Gnoppix Security released a security update for Tomcat 11, fixing multiple vulnerabilities that could allow remote code execution or denial of service. All users running Gnoppix 23/25 or Gnoppix 25 should apply the update immediately.
Vulnerabilities addressed
- Remote code execution via improper input validation in HTTP/2 request handling.
- Denial of service through resource exhaustion when processing multipart requests.
- Information disclosure due to incorrect handling of error messages in the catalina connector.
Action required: Upgrade the
tomcat11package to the latest version using your package manager and restart the service.
Affected releases
- Gnoppix 23/25 (oldstable) – version 11.0.5+dfsg-1+deb12u1
- Gnoppix 25 (stable) – version 11.0.5+dfsg-1+deb13u1
No workarounds are available. Full details are in the advisory referenced as GSA-6329-1. - Please update your systems.