CVE-2025-52434
EUVD-2025-2104510.07.2025, 19:15
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 9.0.107, which fixes the issue.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| apache | tomcat | 9.0.0 ≤ 𝑥 < 9.0.107 |
𝑥
= Vulnerable software versions
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| tomcat |
| ||||||||||||||||||||||||
| tomcat-admin-webapps |
| ||||||||||||||||||||||||
| tomcat-docs-webapp |
| ||||||||||||||||||||||||
| tomcat-el-3_0-api |
| ||||||||||||||||||||||||
| tomcat-javadoc |
| ||||||||||||||||||||||||
| tomcat-jsp-2_3-api |
| ||||||||||||||||||||||||
| tomcat-lib |
| ||||||||||||||||||||||||
| tomcat-servlet-4_0-api |
| ||||||||||||||||||||||||
| tomcat-webapps |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||
|---|---|---|---|---|---|---|---|---|---|
| tomcat |
| ||||||||
| tomcat-admin-webapps |
| ||||||||
| tomcat-docs-webapp |
| ||||||||
| tomcat-el-3.0-api |
| ||||||||
| tomcat-jsp-2.3-api |
| ||||||||
| tomcat-lib |
| ||||||||
| tomcat-servlet-4.0-api |
| ||||||||
| tomcat-webapps |
|