[CLSA-2026:1789375664] Fix CVE(s): CVE-2022-3715
Type:
security
Severity:
Important
Release date:
2026-09-14 08:47:54 UTC
Description:
* SECURITY UPDATE: out-of-bounds read in parameter transformation - debian/patches/CVE-2022-3715.patch: reject an empty transformation operator in parameter_brace_transform before valid_parameter_transform reads past the end of the operator string in subst.c - CVE-2022-3715
CVEs fixed:
Updated packages:
  • bash_5.1-2+deb11u1+tuxcare.els1_amd64.deb
    sha:84e6fb8b3792210787605e018f310616b0f507bb
  • bash-builtins_5.1-2+deb11u1+tuxcare.els1_amd64.deb
    sha:cd8516f9bad705a3ffda496586f62adb607f2d61
  • bash-doc_5.1-2+deb11u1+tuxcare.els1_all.deb
    sha:11e81c3b7aa8dc18114c482255a6e311d7329631
  • bash-static_5.1-2+deb11u1+tuxcare.els1_amd64.deb
    sha:8b77e7eef10f426028fc78c6af135a7baf8a76c3
  • bash_5.1-2+deb11u1+tuxcare.els1_arm64.deb
    sha:f55bd9b7faf70a1f32382524d305e71eeab0f361
  • bash-builtins_5.1-2+deb11u1+tuxcare.els1_arm64.deb
    sha:95d91e2aeec7dc943b5a5ea7749e7a3a163ed30f
  • bash-static_5.1-2+deb11u1+tuxcare.els1_arm64.deb
    sha:dbc8264b57adb5517d1b507a0c66560e69ef7f38
  • bash_5.1-2+deb11u1+tuxcare.els1_armel.deb
    sha:84a02f3920e3a17db123940a22ae929c25e8f437
  • bash-builtins_5.1-2+deb11u1+tuxcare.els1_armel.deb
    sha:85c4dccddc622a37b8d2a6cdc6fcd40f5d43cfa8
  • bash-static_5.1-2+deb11u1+tuxcare.els1_armel.deb
    sha:7849bc11e7ab33d9831b2859086890d717664dcc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.