Release date:
2026-08-11 13:20:26 UTC
Description:
* SECURITY UPDATE: information leak of uninitialized stack memory via an
attacker-controlled checksum length (s2length) in hash_search():
- debian/patches/els/0008-CVE-2024-12085.patch: zero the local sum2
buffer on entry to hash_search().
- CVE-2024-12085.
Updated packages:
-
rsync_3.1.3-6+tuxcare.els4_amd64.deb
sha:3e275efdd87629e7519653c66d19699692053865
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.