ELA-1510-2 libcommons-lang-java regression update

regression update

2025-10-01
Packagelibcommons-lang-java
Version2.6-6+deb9u2 (stretch), 2.6-8+deb10u2 (buster)


The patch to fix CVE-2025-48924 has not been backported correctly and can lead to an unexpected ClassNotFoundException in ClassUtils.getClass(). Updated packages are now available to correct this issue.



For Debian 10 buster, these problems have been fixed in version 2.6-8+deb10u2.

For Debian 9 stretch, these problems have been fixed in version 2.6-6+deb9u2.

We recommend that you upgrade your libcommons-lang-java packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.