{"id":"CLSA-2026-1777446601","summary":"Fix CVE(s): CVE-2020-13935","details":"   * SECURITY UPDATE: denial of service via crafted WebSocket frame with\n     a 64-bit payload length whose most significant bit is set. The\n     extended payload length read in WsFrameBase.processRemainingHeader()\n     was assembled into a Java long without validation. With bit 63 set\n     the value became negative, which the consumer then used as a loop\n     bound, causing an infinite loop and exhausting CPU on the server\n     thread. Affects Apache Tomcat 7.0.0 to 7.0.104, 8.5.0 to 8.5.56,\n     9.0.0.M1 to 9.0.36, and 10.0.0-M1 to 10.0.0-M6.\n     - debian/patches/CVE-2020-13935.patch: validate the 64-bit payload\n       length in processRemainingHeader() and reject frames with a\n       negative value by throwing a WsIOException carrying a\n       PROTOCOL_ERROR close reason; add the wsFrame.payloadMsbInvalid\n       message to LocalStrings.properties. Also fold the companion fix\n       4c04982870 to apply the same validation to the legacy\n       org/apache/catalina/websocket/WsFrame parser (still packaged in\n       catalina.jar via WebSocketServlet), and the regression follow-up\n       34d19fbe24 in WsFrameBase.byteArrayToLong() (0xFF -\u003e 0xFFL) that\n       prevents silent corruption of payload lengths \u003e= 4 bytes from\n       int-shift promotion. Additionally fold b517002093 to apply the\n       same 0xFF -\u003e 0xFFL fix to the parallel helper\n       Conversions.byteArrayToLong() in\n       java/org/apache/catalina/util/Conversions.java, which is the\n       helper used by the legacy WsFrame parser; without it the new\n       \u003c 0 check in the legacy parser would falsely reject legitimate\n       large frames. Backport of upstream commits f9f75c14, 34d19fbe24,\n       4c04982870 and b517002093\n       (https://github.com/apache/tomcat/commit/f9f75c14\n        https://github.com/apache/tomcat/commit/34d19fbe24\n        https://github.com/apache/tomcat/commit/4c04982870\n        https://github.com/apache/tomcat/commit/b517002093)\n     - CVE-2020-13935","modified":"2026-06-04T09:46:54.265179181Z","published":"2026-04-29T07:10:05Z","upstream":["CVE-2020-13935"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2026-1777446601.html"}],"affected":[{"package":{"name":"libservlet3.0-java","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libservlet3.0-java?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"libservlet3.0-java-doc","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libservlet3.0-java-doc?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"libtomcat7-java","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/libtomcat7-java?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"tomcat7","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"tomcat7-admin","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-admin?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"tomcat7-common","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-common?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"tomcat7-docs","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-docs?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"tomcat7-examples","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-examples?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}},{"package":{"name":"tomcat7-user","ecosystem":"TuxCare:Ubuntu:16.04","purl":"pkg:deb/tuxcare/tomcat7-user?distro=ubuntu-16.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1ubuntu0.4+tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu16.04els/CLSA-2026-1777446601.json"}}],"schema_version":"1.7.5"}