CLSA-2025-1764580671

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1764580671.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2025-1764580671
Upstream
Published
2025-12-01T19:08:17Z
Modified
2026-06-01T00:31:21.750839627Z
Summary
pki-servlet-engine: Fix of 2 CVEs
Details
  • CVE-2024-50379: fix TOCTOU vulnerability in JSP compilation to prevent RCE on case insensitive file systems
  • CVE-2024-38286: fix issue of resource allocation without limits or throttling vulnerability in TLS handshake process
  • Apply skip-common-daemon patch to remove the commons-daemon.jar copy in build.xml, as Alma/RHEL cannot ship bundled JARs and must use the system commons-daemon The ELS-provided source archive requires this adaptation
References

Affected packages

TuxCare:AlmaLinux:9.2 / pki-servlet-4.0-api

Package

Name
pki-servlet-4.0-api
Purl
pkg:rpm/tuxcare/pki-servlet-4.0-api?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.0.50-1.el9.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1764580671.json"

TuxCare:AlmaLinux:9.2 / pki-servlet-engine

Package

Name
pki-servlet-engine
Purl
pkg:rpm/tuxcare/pki-servlet-engine?distro=almalinux-9.2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:9.0.50-1.el9.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.2esu/CLSA-2025-1764580671.json"