Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-65183

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

A flaw was found in Apache Tomcat. A Time-of-check Time-of-use (TOCTOU) race condition exists when creating Unix domain sockets. This vulnerability allows an unauthorized local user to exploit the timing window to gain access to the Unix domain socket. This could lead to information disclosure or other unauthorized operations.

Отчет

This vulnerability in Apache Tomcat is rated Low. It involves a Time-of-check Time-of-use (TOCTOU) race condition when creating Unix domain sockets, which could allow a local attacker to gain unauthorized access to the socket. Exploitation requires local access and a specific timing window, limiting its impact to information disclosure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatUnder investigation
Red Hat Enterprise Linux 10tomcat9Under investigation
Red Hat Enterprise Linux 6tomcat6Under investigation
Red Hat Enterprise Linux 7tomcatUnder investigation
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineUnder investigation
Red Hat Enterprise Linux 8tomcatUnder investigation
Red Hat Enterprise Linux 9tomcatUnder investigation
Red Hat JBoss Web Server 5tomcatOut of support scope
Red Hat JBoss Web Server 6tomcatAffected
Red Hat JBoss Web Server 7tomcatAffected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2524153tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition

EPSS

Процентиль: 39%
0.00452
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
27 дней назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

CVSS3: 8.1
nvd
27 дней назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

CVSS3: 8.1
debian
27 дней назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apa ...

CVSS3: 8.1
github
27 дней назад

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.

EPSS

Процентиль: 39%
0.00452
Низкий

2.5 Low

CVSS3