ELA-1510-1 libcommons-lang-java security update

uncontrolled recursion vulnerability

2025-08-31
Packagelibcommons-lang-java
Version2.6-6+deb9u1 (stretch), 2.6-8+deb10u1 (buster)
Related CVEs CVE-2025-48924


A vulnerability was discovered in Apache Commons Lang utility classes, a Java API for classes that are in java.lang’s hierarchy.

CVE-2025-48924

An uncontrolled recursion vulnerability was discovered in Apache Commons
Lang. The method ClassUtils.getClass() can throw a StackOverflowError
on very long inputs.


For Debian 10 buster, these problems have been fixed in version 2.6-8+deb10u1.

For Debian 9 stretch, these problems have been fixed in version 2.6-6+deb9u1.

We recommend that you upgrade your libcommons-lang-java packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.