From 6d8b5c2784ffe66f4dc41a09b1e91fc75d254a6f54b2340fb4222d6005872034 Mon Sep 17 00:00:00 2001 From: mbussolotto Date: Mon, 25 Aug 2025 15:30:41 +0200 Subject: [PATCH] - Update to Tomcat 10.1.44 --- apache-tomcat-10.1.43-src.tar.gz | 3 --- apache-tomcat-10.1.43-src.tar.gz.asc | 16 ------------ apache-tomcat-10.1.44-src.tar.gz | 3 +++ apache-tomcat-10.1.44-src.tar.gz.asc | 16 ++++++++++++ tomcat10.changes | 39 ++++++++++++++++++++++++++++ tomcat10.spec | 2 +- 6 files changed, 59 insertions(+), 20 deletions(-) delete mode 100644 apache-tomcat-10.1.43-src.tar.gz delete mode 100644 apache-tomcat-10.1.43-src.tar.gz.asc create mode 100644 apache-tomcat-10.1.44-src.tar.gz create mode 100644 apache-tomcat-10.1.44-src.tar.gz.asc diff --git a/apache-tomcat-10.1.43-src.tar.gz b/apache-tomcat-10.1.43-src.tar.gz deleted file mode 100644 index c518cdc..0000000 --- a/apache-tomcat-10.1.43-src.tar.gz +++ /dev/null @@ -1,3 +0,0 @@ -version https://git-lfs.github.com/spec/v1 -oid sha256:c8135438b1f4a49bfd6c2a6822396715e61d5fea59899fcc4c94c4e9675a16c3 -size 7226931 diff --git a/apache-tomcat-10.1.43-src.tar.gz.asc b/apache-tomcat-10.1.43-src.tar.gz.asc deleted file mode 100644 index 88ff46a..0000000 --- a/apache-tomcat-10.1.43-src.tar.gz.asc +++ /dev/null @@ -1,16 +0,0 @@ ------BEGIN PGP SIGNATURE----- - -iQIzBAABCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAmhkU9cACgkQHPApP6U8 -pFhElw/+PtORhhIobN6tQaSZYWQ8wfgNnd+gYpT31sp7ufUmKpHDYU0/FeU/kCmZ -FEIPbxPfEA4vHjbJh6E+sN59+s8HO5A255M3qum/NIJW8XsN5EdZcn+8fZVogMp7 -jWtnB7A9TPZ32mOljY7GXfXe4Da7PUoH8DZgD+eJ/iXrYoK6dgha5Z0cUQWuHq7j -h/nCajbnNhsicIipAXUlUEwkWi6br3CPSFTdULmG9WvxgUEvKetSftOScqtOCE5C -Tb5SZFyHuui2BAT9d6D6Varjae8GcpvkBupa6YhL981jERrGybo38IfSP2HWAlwP -vQIuCGkhSoe/Nn65f2UxMiftyWPY8AgyedRFzE2EXxyxWZCOXksbovvqlhKxoStk -MofhhAMhNApdk7d+wipuLcjRXdQBXo5PSo0782uDE+Fyl7sTl7dRnVmQNCTyrVUg -/bFqMUzuQS7znqXNj+0yD9x1aC+LeiNMsvYTfPihqv7SeJUqz10CyqkkO8aYetGJ -RhHlcrzl0+hsCzyYV8W2BG28GHfTRxSfYA43tlTqg5c7BFzOs3NlJFLwMcxToszw -7Lb2xXevGnBRSM27UbXeLFXr9/xDiMu9C0fxAIpCNKhFVIidNoJ/vvIkMtj38xzT -DWz0EQB/8TSwfEmqs+c5uppziZa7eN6iJfWBp18IqPLC1wPgKGY= -=VK2I ------END PGP SIGNATURE----- diff --git a/apache-tomcat-10.1.44-src.tar.gz b/apache-tomcat-10.1.44-src.tar.gz new file mode 100644 index 0000000..2428ed3 --- /dev/null +++ b/apache-tomcat-10.1.44-src.tar.gz @@ -0,0 +1,3 @@ +version https://git-lfs.github.com/spec/v1 +oid sha256:c1309c127b6e96568bacfe34e405a8f69b6d716630f69f680480debc7aed1c11 +size 7247899 diff --git a/apache-tomcat-10.1.44-src.tar.gz.asc b/apache-tomcat-10.1.44-src.tar.gz.asc new file mode 100644 index 0000000..254b4d0 --- /dev/null +++ b/apache-tomcat-10.1.44-src.tar.gz.asc @@ -0,0 +1,16 @@ +-----BEGIN PGP SIGNATURE----- + +iQIzBAABCAAdFiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAmiQsokACgkQHPApP6U8 +pFgXgBAAiqI8kGmeyVtr0mqgwHibJK8EnjUBcsiFzV2PdTSsGKX7Xk5GBkR7xJ5i +3MZJw44irpJmaQdkcMVfB5IlUx/xNqEXsAd1Ac1xrJFSxA8xqgPD7Wsec1bruR6s +Wac3c5d1uqasq8Scu95NsSjWvXc4kr3fkUk9dTCAyUcrtXwQffibXN1MZwuKvG+5 +/49h8IbVTxutj0mp45WnyxTa5yiITkX1homdXv5L1Y+TqdGaR7gagKGQAoTUeGL+ +UR3pmDP2720SleMbmTWjSZqykOxpnBgsOL7UNoGzzu/wMW4HKGZAfvjxWPq8oyPq +mPGQbHPtDkOzak/Eb+CBkrYE78KO9Iv9qgJ1JhTRzuGncLvNZ1RMmxxhGJr0uR9+ +qHdKHsGAIJI9Mj8dZLWoBkpKJq/OjxXBnKu1U+ax5nocOegvk7xK9TZ6YbxoSBmW +JtDRE0GLSA9CfL22xhFSfQMG/l+WMdQi5vwrHPTB9GW2HxS0Oc+L8rKfxovM5rUb +17rMa+wyJgPfc2efSaJwMPz+8AZEV7IrMwiqDx5cUegdgCG5z8n9EOVyL+iJgZp5 +EdUpQxNWnLil9YP4zkqHauJXNCBwcXZyUiNhuQRLBGT/hkBk6SD2WKC1qz42dGK6 +8zyulJBo/ninEQPnXzIDysHFd+/lXuo7vknKC3DAQtDESGF6MHY= +=h0AE +-----END PGP SIGNATURE----- diff --git a/tomcat10.changes b/tomcat10.changes index 651d238..f103ecd 100644 --- a/tomcat10.changes +++ b/tomcat10.changes @@ -1,3 +1,42 @@ +------------------------------------------------------------------- +Mon Aug 25 13:28:00 UTC 2025 - Michele Bussolotto + +- Update to Tomcat 10.1.44 + * Fixed CVEs: + + CVE-2025-48989: Update the HTTP/2 overhead documentation (bsc#1243895) + * Catalina + + Fix: Fix bloom filter population for archive indexing when using a packed + WAR containing one or more JAR files. (markt) + * Coyote + + Fix: 69748: Add missing call to set keep-alive timeout when using + HTTP/1.1 following an async request, which was present for AJP. + (remm/markt) + + Fix: 69762: Fix possible overflow during HPACK decoding of integers. Note + that the maximum permitted value of an HPACK decoded integer is + Integer.MAX_VALUE. (markt) + + Fix: Update the HTTP/2 overhead documentation - particularly the code + comments - to reflect the deprecation of the PRIORITY frame and clarify + that a stream reset always triggers an overhead increase. (markt) + + Fix: 69762: Additional overflow fix for HPACK decoding of integers. Pull + request #880 by Chenjp. (markt) + * Cluster + + Update: Add enableStatistics configuration attribute for the + DeltaManager, defaulting to true. (remm) + * WebSocket + + Fix: Align the WebSocket extension handling for WebSocket client + connections with WebSocket server connections. The WebSocket client now + only includes an extension requested by an endpoint in the opening + handshake if the WebSocket client supports that extension. (markt) + * Web applications + + Fix: Manager and Host Manager. Provide the Manager and Host Manager web + applications with a dedicated favicon file rather than using the one from + the ROOT web application which might not be present or may represent + something entirely different. Pull requests #876 and #878 by Simon Arame. + * Other + + Update: Update Checkstyle to 10.26.1. (markt) + + Add: Improvements to French translations. (remm) + + Add: Improvements to Japanese translations by tak7iji. (markt) + ------------------------------------------------------------------- Wed Aug 6 12:45:13 UTC 2025 - Michele Bussolotto diff --git a/tomcat10.spec b/tomcat10.spec index 66c6980..0048a79 100644 --- a/tomcat10.spec +++ b/tomcat10.spec @@ -29,7 +29,7 @@ %define elspec %{elspec_major}.%{elspec_minor} %define major_version 10 %define minor_version 1 -%define micro_version 43 +%define micro_version 44 %define java_major 1 %define java_minor 11 %define java_version %{java_major}.%{java_minor} -- 2.49.0