[CLSA-2026:1789748401] Fix CVE(s): CVE-2025-14932
Type:
security
Severity:
Important
Release date:
2026-09-18 16:20:12 UTC
Description:
* SECURITY UPDATE: stack buffer overflow in cdParseRelunits() and is_valid_time_unit() - debian/patches/CVE-2025-14932.patch: bound the sscanf conversions that parse the time units attribute to the destination buffer sizes - CVE-2025-14932
CVEs fixed:
Updated packages:
  • libnetcdf-dev_4.7.4-1+tuxcare.els2_amd64.deb
    sha:0cd60e8a88a299d0041bc1c0383fda07e28057f7
  • libnetcdf18_4.7.4-1+tuxcare.els2_amd64.deb
    sha:4059541a43ad4fc971d0047a1598930e0138a492
  • netcdf-bin_4.7.4-1+tuxcare.els2_amd64.deb
    sha:5b2638fe0718f9f726ca2f79d09f8b4ceba34dd5
  • netcdf-doc_4.7.4-1+tuxcare.els2_all.deb
    sha:f63063f1dd6fc4bf677972954185dbff92b52747
  • libnetcdf-dev_4.7.4-1+tuxcare.els2_arm64.deb
    sha:aeeb290675e6d5b3980852ea12a8687ef8dac8ff
  • libnetcdf18_4.7.4-1+tuxcare.els2_arm64.deb
    sha:5fdfb70cb3d2a315ca0f508ad0769f01e1c89a83
  • netcdf-bin_4.7.4-1+tuxcare.els2_arm64.deb
    sha:467b415b83bc03352023d001b36e7eb8baada911
  • libnetcdf-dev_4.7.4-1+tuxcare.els2_armel.deb
    sha:449ef920697158d54479474316fe17fdb695f77d
  • libnetcdf18_4.7.4-1+tuxcare.els2_armel.deb
    sha:24b1c03cbd6c808dd9c4e5c7f6080abaf9192205
  • netcdf-bin_4.7.4-1+tuxcare.els2_armel.deb
    sha:8f0e1d7b7474cd614eccb225e1fc4832c56a41db
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.