Release date:
2026-09-22 11:07:50 UTC
Description:
- CVE-2026-11972: break out of the block loop in tarfile._Stream.seek as soon
as read() returns no data, so a member header declaring a huge size can no
longer keep a stream-mode archive spinning until it is interrupted
- CVE-2026-9669: latch the libbz2 error code in BZ2Decomp_decompress and raise
ValueError on any later call, so a BZ2Decompressor cannot be re-entered
after a decompression error and write outside its output buffer; the same
error is latched on BZ2FileObject through the new Util_BzRead wrapper, so a
BZ2File whose stream already errored re-reports that IOError on every later
read instead of re-entering BZ2_bzDecompress
Updated packages:
-
python2-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:ff5765b4b357eb25c383edd5dce178adda731e1d63d368490bde9374363daf00
-
python2-debug-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:aa30802ea3ec5210e77589ef13ea50da9fd90c5aefaad2d7b6f4ebcf1db22787
-
python2-devel-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:5d4fca9307d32c4cc760ca2d13476f77f20fed74515367a4934185696757c9ae
-
python2-libs-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:f21e7e485eb850263349a91cdcf6aa7efe32a23b6aee0d47599fe69ee191120d
-
python2-test-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:ca3d19380134463b5f430e90eff664220e9532212c62aaa3d2dfc0df555f9ead
-
python2-tkinter-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:9c0fa85ca85b320794efd310450c6478b1f0b4d08ba98e91dd59439f6419e67a
-
python2-tools-2.7.18-17.module_el8+2579+f2359962.tuxcare.els16.x86_64.rpm
sha:e33599544da70da855fa0c07e16a4eb161640a70e2a4145b6c629619bc2bedc5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.