Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:1751-1

Опубликовано: 07 мая 2026
Источник: suse-cvrf

Описание

Security update for jetty-minimal

This update for jetty-minimal fixes the following issues:

  • CVE-2026-2332: In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the 'funky chunks' techniques (bsc#1262115).
  • CVE-2026-5795: Fixed JaspiAuthenticator broken access control (bsc#1261997).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Module for Development Tools 15 SP7
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
jetty-continuation-9.4.58-150200.3.40.1
SUSE Linux Enterprise Server 15 SP4-LTSS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Server 15 SP5-LTSS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Server 15 SP6-LTSS
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
jetty-http-9.4.58-150200.3.40.1
jetty-io-9.4.58-150200.3.40.1
jetty-security-9.4.58-150200.3.40.1
jetty-server-9.4.58-150200.3.40.1
jetty-servlet-9.4.58-150200.3.40.1
jetty-util-9.4.58-150200.3.40.1
jetty-util-ajax-9.4.58-150200.3.40.1

Описание

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chunk extension parsing at \r\n inside quoted strings instead of treating this as an error. POST / HTTP/1.1 Host: localhost Transfer-Encoding: chunked 1;ext="val X 0 GET /smuggled HTTP/1.1 ... Note how the chunk extension does not close the double quotes, and it is able to inject a smuggled request.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-http-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-io-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-security-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-server-9.4.58-150200.3.40.1

Ссылки

Описание

In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. A subsequent request using the same thread inherits the ThreadLocal values, leading to a broken access control and privilege escalation.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-http-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-io-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-security-9.4.58-150200.3.40.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:jetty-server-9.4.58-150200.3.40.1

Ссылки