[CLSA-2026:1786454415] Fix CVE(s): CVE-2024-12085
Type:
security
Severity:
Important
Release date:
2026-08-11 13:20:26 UTC
Description:
* SECURITY UPDATE: information leak of uninitialized stack memory via an attacker-controlled checksum length (s2length) in hash_search(): - debian/patches/els/0008-CVE-2024-12085.patch: zero the local sum2 buffer on entry to hash_search(). - CVE-2024-12085.
CVEs fixed:
Updated packages:
  • rsync_3.1.3-6+tuxcare.els4_amd64.deb
    sha:3e275efdd87629e7519653c66d19699692053865
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.