UbuntuUpdates.org

Package "libcommons-lang3-java"

Name: libcommons-lang3-java

Description:

Apache Commons Lang utility classes

Latest version: 3.11-1ubuntu0.1
Release: jammy (22.04)
Level: updates
Repository: universe
Homepage: http://commons.apache.org/lang/

Links


Download "libcommons-lang3-java"


Other versions of "libcommons-lang3-java" in Jammy

Repository Area Version
base universe 3.11-1
security universe 3.11-1ubuntu0.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.11-1ubuntu0.1 2026-06-02 20:07:30 UTC

  libcommons-lang3-java (3.11-1ubuntu0.1) jammy-security; urgency=medium

  * SECURITY UPDATE: denial-of-service due to stack overflow
    - debian/patches/CVE-2025-48924.patch: Rewrite ClassUtils.getClass() without
      recursion to avoid StackOverflowError on very long inputs in
      src/main/java/org/apache/commons/lang3/ClassUtils.java. Add test in
      src/test/java/org/apache/commons/lang3/ClassUtilsOssFuzzTest.java.
    - CVE-2025-48924

 -- Edwin Jiang <email address hidden> Fri, 29 May 2026 19:25:43 -0400

CVE-2025-48924 Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to



About   -   Send Feedback to @ubuntu_updates