[CLSA-2026:1776962104] bzip2: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-24 18:38:58 UTC
Description:
- CVE-2019-12900: fix out-of-bounds write in BZ2_decompress when many selectors are present - CVE-2016-3189: fix use-after-free in bzip2recover
Updated packages:
  • bzip2-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:81cd83fdb41b28777bdf2d8768b330965ebbf9c5d3bbe67fef25b7ed836019ae
  • bzip2-devel-1.0.6-13.el7.tuxcare.els1.i686.rpm
    sha:623c81c4826786ed6a7c1579752dbe8f24c33cbd65bd345b6c4de8ff9059e1d0
  • bzip2-devel-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:f94428457b6c4eaf4e1f296be8ea1f57667e451da0547490e2b1408e11c3d965
  • bzip2-libs-1.0.6-13.el7.tuxcare.els1.i686.rpm
    sha:016b816118500c027617e54fe43a55f501e2db4485dd3d30f106203ac89756b2
  • bzip2-libs-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:301d041a3c43044032b73194efaaf59745de62a779732dd2dc62a6b61e551a10
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.