Bug 2524153 (CVE-2026-65183)
| Summary: | CVE-2026-65183 tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | csutherl, dsoumis, jclere, jwon, pjindal, plodge, rhel-process-autobot, rmaucher, szappis, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Apache Tomcat. A Time-of-check Time-of-use (TOCTOU) race condition exists when creating Unix domain sockets. This vulnerability allows an unauthorized local user to exploit the timing window to gain access to the Unix domain socket. This could lead to information disclosure or other unauthorized operations.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-08-25 22:01:58 UTC
This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2.5 Via RHSA-2026:73982 https://access.redhat.com/errata/RHSA-2026:73982 This issue has been addressed in the following products: Red Hat JBoss Web Server 6.2 on RHEL 10 Red Hat JBoss Web Server 6.2 on RHEL 8 Red Hat JBoss Web Server 6.2 on RHEL 9 Via RHSA-2026:73981 https://access.redhat.com/errata/RHSA-2026:73981 |