Release date:
2026-09-17 19:04:10 UTC
Description:
* SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER decoding
- debian/patches/CVE-2026-59885.patch: accumulate arcs in a list instead
of repeated tuple concatenation in the BER decoder and encoder
- CVE-2026-59885
* SECURITY UPDATE: Uncontrolled resource consumption converting univ.Real
- debian/patches/CVE-2026-59886.patch: use math.ldexp for base 2 and
reject base-10 exponents above sys.float_info.max_10_exp in
Real.__float__, instead of exact big-integer exponentiation
- CVE-2026-59886
Updated packages:
-
pypy-pyasn1_0.4.8-1+deb11u2+tuxcare.els1_all.deb
sha:017ca97cdb0a4e94cbf6b5c40aca36448989c57c
-
python-pyasn1-doc_0.4.8-1+deb11u2+tuxcare.els1_all.deb
sha:f16abd8e63ca26e0cd16004c9ec49ee2c649e436
-
python3-pyasn1_0.4.8-1+deb11u2+tuxcare.els1_all.deb
sha:49f6bd8be290817fbc7acfc6e0f19b79e8d6a5c2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.