---
title: "CVE-2022-25762\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-25762?format=md
keywords: index, follow
---

# CVE-2022-25762

Publication date 13 May 2022

Last updated 21 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**8.6 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2022-25762?format=md#impact-score)

Toggle side navigation

## Description

If a web application sends a WebSocket message concurrently with the
WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75
or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application
will continue to use the socket after it has been closed. The error
handling triggered in this case could cause the a pooled object to be
placed in the pool twice. This could result in subsequent connections using
the same object concurrently which could result in data being returned to
the wrong use and/or other errors.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| tomcat8 | 18.04 LTS bionic | Vulnerable |
| 16.04 LTS xenial | Not affected |
| tomcat9 | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

8.6 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | Low |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 8.6 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-25762)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-25762)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-25762)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-25762)

### Other references

* <https://github.com/apache/tomcat/commit/e2d5a040b962a904db5264b3cb3282c6b05f823c (9.0.21)>
* <https://github.com/apache/tomcat/commit/7046644bf361b89afc246b6643e24ce2ae60cacc (9.0.21)>
* <https://github.com/apache/tomcat/commit/339b40bc07bdba9ded565929b9a3448c5a78f015 (9.0.21)>
* <https://github.com/apache/tomcat/commit/65fb1ee548111021edde247f3b3c409ec95a5183 (9.0.21)>
* <https://github.com/apache/tomcat/commit/01f2cf25b270a84d0daeefc4f215aa2f56e1df99 (8.5.76)>
* <https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c>
* <https://www.cve.org/CVERecord?id=CVE-2022-25762>
