Bug 2362783 (CVE-2025-31650)

Summary: CVE-2025-31650 tomcat: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: aogburn, cchiang, csutherl, jclere, pdelbell, pjindal, plodge, prodsec-dev, szappis, vrajput
Target Milestone: ---Keywords: Security
Target Release: ---Flags: szappis: needinfo? (pdelbell)
aogburn: needinfo? (prodsec-dev)
aogburn: needinfo? (pdelbell)
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache Tomcat. This vulnerability allows an application-level denial of service (DoS), causing it to become unresponsive or slow via maliciously crafted HTTP/2 prioritization headers. It performs an incomplete cleanup of failed requests, which triggers a memory leak.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2363043, 2363044, 2363045    
Bug Blocks:    

Description OSIDB Bzimport 2025-04-28 20:01:21 UTC
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.

This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.

Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

Comment 8 VIRENDRASINGH RAJPUT 2025-05-12 07:13:31 UTC
Hi Engineering Team,

One of the below account too looking for an update and asking to prioritize the fix for this CVE for RHEL 8:

Account Name	ACE-IT/LOCKEED MARTIN	
Account Number	1203914	

Thank You!!

Comment 12 errata-xmlrpc 2025-05-19 10:12:57 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server

Via RHSA-2025:3609 https://access.redhat.com/errata/RHSA-2025:3609

Comment 13 errata-xmlrpc 2025-05-19 10:13:14 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 6.1 on RHEL 8
  Red Hat JBoss Web Server 6.1 on RHEL 9

Via RHSA-2025:3608 https://access.redhat.com/errata/RHSA-2025:3608

Comment 14 errata-xmlrpc 2025-05-19 10:13:24 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server

Via RHSA-2025:4522 https://access.redhat.com/errata/RHSA-2025:4522

Comment 15 errata-xmlrpc 2025-05-19 10:13:32 UTC
This issue has been addressed in the following products:

  Red Hat JBoss Web Server 5.8 on RHEL 7
  Red Hat JBoss Web Server 5.8 on RHEL 8
  Red Hat JBoss Web Server 5.8 on RHEL 9

Via RHSA-2025:4521 https://access.redhat.com/errata/RHSA-2025:4521

Comment 16 errata-xmlrpc 2025-07-16 15:12:57 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:11332 https://access.redhat.com/errata/RHSA-2025:11332

Comment 17 errata-xmlrpc 2025-07-16 15:21:46 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:11334 https://access.redhat.com/errata/RHSA-2025:11334

Comment 18 errata-xmlrpc 2025-07-16 15:22:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:11335 https://access.redhat.com/errata/RHSA-2025:11335

Comment 19 errata-xmlrpc 2025-07-16 15:25:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:11333 https://access.redhat.com/errata/RHSA-2025:11333

Comment 20 errata-xmlrpc 2025-07-17 10:51:01 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:11381 https://access.redhat.com/errata/RHSA-2025:11381

Comment 21 errata-xmlrpc 2025-07-17 11:02:24 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:11382 https://access.redhat.com/errata/RHSA-2025:11382