> USN-8369-2: mod_jk regression
[DATE: 23/07/2026 00:33]
[LANGUAGE: EN]
USN-8369-1 fixed a vulnerability in mod_jk. It was discovered that for
Ubuntu 18.04 LTS, during the update preparation phase, a previous fix for
CVE-2023-41081 was incorrectly dropped. This update reintroduces the fix
for CVE-2023-41081.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Apache Tomcat Connectors used incorrect default
permissions for shared memory on Unix-like systems. A local attacker could
possibly use this issue to view or modify mod_jk configuration data in
shared memory, resulting in sensitive information exposure or a denial of
service.