Bug 34377 - apache-commons-fileupload new security issue CVE-2025-48976
Summary: apache-commons-fileupload new security issue CVE-2025-48976
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-06-18 15:55 CEST by Nicolas Salguero
Modified: 2025-11-15 08:17 CET (History)
4 users (show)

See Also:
Source RPM: apache-commons-fileupload-1.4-5.mga9.src.rpm
CVE: CVE-2025-48976
Status comment:


Attachments

Description Nicolas Salguero 2025-06-18 15:55:07 CEST
CVE-2025-48976 was announced here:
https://www.openwall.com/lists/oss-security/2025/06/16/4
Nicolas Salguero 2025-06-18 15:56:29 CEST

CVE: (none) => CVE-2025-48976
Whiteboard: (none) => MGA9TOO
Status comment: (none) => Fixed upstream in 1.6
Source RPM: (none) => apache-commons-fileupload-1.4-5.mga9.src.rpm

Comment 1 Marja Van Waes 2025-06-18 21:19:32 CEST
Assigning to the registered maintainer, CC'ing daviddavid

CC: (none) => geiger.david68210, marja11
Assignee: bugsquad => mageia

Comment 2 Nicolas Salguero 2025-07-01 13:37:32 CEST
openSUSE has issued an advisory on June 27:
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/O4NTTRMGJEETFRWJKHNAERLI3E52LN2W/
Comment 3 Nicolas Salguero 2025-11-14 15:09:52 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Apache Commons FileUpload, Apache Commons FileUpload: FileUpload DoS via part headers. (CVE-2025-48976)

References:
https://www.openwall.com/lists/oss-security/2025/06/16/4
https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/O4NTTRMGJEETFRWJKHNAERLI3E52LN2W/
========================

Updated packages in core/updates_testing:
========================
apache-commons-fileupload-1.4-5.1.mga9
apache-commons-fileupload-javadoc-1.4-5.1.mga9

from SRPM:
apache-commons-fileupload-1.4-5.1.mga9.src.rpm

Assignee: mageia => qa-bugs
Whiteboard: MGA9TOO => (none)
Status: NEW => ASSIGNED
Version: Cauldron => 9
Status comment: Fixed upstream in 1.6 => (none)

Comment 4 katnatek 2025-11-15 01:23:43 CET
installing apache-commons-fileupload-1.4-5.1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ###################################################################################################
      1/1: apache-commons-fileupload
                                 ###################################################################################################
      1/1: removing apache-commons-fileupload-1.4-5.mga9.noarch
                                 ###################################################################################################

Clean update
systemctl restart httpd.service 
systemctl status httpd.service 
● httpd.service - The Apache HTTP Server
     Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; preset: disabled)
     Active: active (running) since Fri 2025-11-14 18:23:52 CST; 2s ago
   Main PID: 4753 (httpd)
     Status: "Processing requests..."
      Tasks: 6 (limit: 6823)
     Memory: 6.1M
        CPU: 62ms
     CGroup: /system.slice/httpd.service
             ├─4753 /usr/sbin/httpd -DFOREGROUND
             ├─4756 /usr/sbin/httpd -DFOREGROUND
             ├─4758 /usr/sbin/httpd -DFOREGROUND
             ├─4759 /usr/sbin/httpd -DFOREGROUND
             ├─4760 /usr/sbin/httpd -DFOREGROUND
             └─4761 /usr/sbin/httpd -DFOREGROUND

nov 14 18:23:52 jgrey.phoenix systemd[1]: Starting httpd.service...
nov 14 18:23:52 jgrey.phoenix systemd[1]: Started httpd.service.

Whiteboard: (none) => MGA9-64-OK

katnatek 2025-11-15 01:29:38 CET

Keywords: (none) => advisory

Comment 5 Thomas Andrews 2025-11-15 02:55:17 CET
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 6 Mageia Robot 2025-11-15 08:17:20 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0296.html

Resolution: (none) => FIXED
Status: ASSIGNED => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.