[CLSA-2026:1776965760] bzip2: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-23 17:36:05 UTC
Description:
- CVE-2019-12900: fix out-of-bounds write in BZ2_decompress when many selectors are present - CVE-2016-3189: fix use-after-free in bzip2recover
Updated packages:
  • bzip2-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:47ad5a0110b9ac833daa6f3c4a0cae6be63f51e1da196f74008a738f2935c5a9
  • bzip2-devel-1.0.6-13.el7.tuxcare.els1.i686.rpm
    sha:19c49bf54b76d39cb06834f05bfc457e2ee5ec8def4138615089a6525a914e5a
  • bzip2-devel-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:9c165bddd64fdf866876d1ac4f4c8082d28dbe204b01f6f5b06b7ec5ebd68572
  • bzip2-libs-1.0.6-13.el7.tuxcare.els1.i686.rpm
    sha:6af553b49f0b6ada175c5945e64a2069d7fc7fffc71c58c33017d6dcfffe7a94
  • bzip2-libs-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:af7e049e43e616f51bddfef787af253891dd15d6bd9e80749eae3b689e51e1e5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.