jmc-8.2.0-19.el9_8.2
エラータID: AXSA:2026-1271:02
リリース日:
2026/07/16 Thursday - 17:31
題名:
jmc-8.2.0-19.el9_8.2
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- lz4-java の Java ベースの展開処理の実装には、データの初期化
処理が欠落しているため、リモートの攻撃者により、情報の漏洩を可能
とする脆弱性が存在します。(CVE-2025-66566)
- Eclipse Jetty の HTTP/1.1 パーサーには、リモートの攻撃者により、
巧妙に細工された HTTP リクエストを介して、HTTP リクエストスマグ
リング攻撃、キャッシュポイズニング攻撃、アクセス制御のバイパス、
およびセッションハイジャックを可能とする脆弱性が存在します。
(CVE-2026-2332)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2025-66566
yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1.
yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1.
CVE-2026-2332
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.
追加情報:
N/A
ダウンロード:
SRPMS
- jmc-8.2.0-19.el9_8.2.src.rpm
MD5: e09130a688e9ace7b8579b4a199f94e4
SHA-256: c1ab60c27d197e9c6583a9317216e25e308fb100baf421884d8bae13271006d7
Size: 423.87 MB
Asianux Server 9 for x86_64
- jmc-8.2.0-19.el9_8.2.x86_64.rpm
MD5: 8a834c8d8a416aa5a00262570fc05b93
SHA-256: b0a43fdee87aa3662b59471ddc992691e2d81c96a75f9ee50aba93509d266833
Size: 72.56 MB