[CLSA-2026:1789205560] Fix CVE(s): CVE-2026-41992
Type:
security
Severity:
Important
Release date:
2026-09-12 09:32:51 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in the LZH decoder - debian/patches/CVE-2026-41992.patch: clear left, right and c_table in huf_decode_start() in unlzh.c - CVE-2026-41992
CVEs fixed:
Updated packages:
  • gzip_1.10-4+deb11u1+tuxcare.els1_amd64.deb
    sha:a8d07c9d13154e147650e93d9841a13093a2fd28
  • gzip-win32_1.10-4+deb11u1+tuxcare.els1_all.deb
    sha:7f2d83f609bec5890330d231899ee345fbd04283
  • gzip_1.10-4+deb11u1+tuxcare.els1_arm64.deb
    sha:79aec2959d70d8320894e088770fedc43375ee05
  • gzip_1.10-4+deb11u1+tuxcare.els1_armel.deb
    sha:c5c8e7f000d02767c7bdaa2a43ecb6043c9dd626
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.