[CLSA-2026:1776961553] bzip2: Fix of 2 CVEs
Type:
security
Severity:
Critical
Release date:
2026-04-23 16:25:58 UTC
Description:
- CVE-2019-12900: fix out-of-bounds write in BZ2_decompress when many selectors are present - CVE-2016-3189: fix use-after-free in bzip2recover
Updated packages:
  • bzip2-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:f24b1259520fc77aa4ad87aa374ac48a38e0b705f7bcff87c5a1f7a0eb5a7fe2
  • bzip2-devel-1.0.6-13.el7.tuxcare.els1.i686.rpm
    sha:49e70a0476dcdd8f76f0425f5dd9de4174d62798f86e8fc64eccf015b4396e5f
  • bzip2-devel-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:411d4ffed496925d03389fff363e51ee83d89b9b84b11b453bf34d0596e64805
  • bzip2-libs-1.0.6-13.el7.tuxcare.els1.i686.rpm
    sha:24e138e58696e579c5160ecb215d2181b41adab975d57371ccfbd125940155cd
  • bzip2-libs-1.0.6-13.el7.tuxcare.els1.x86_64.rpm
    sha:354bc14bde789284d1a25a0e204535f76f6393b55b23b4a29f32726331b210a0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.