[CLSA-2026:1785489136] Fix CVE(s): CVE-2026-11386, CVE-2026-12391, CVE-2026-9494
Type:
security
Severity:
Important
Release date:
2026-07-31 09:12:32 UTC
Description:
* SECURITY UPDATE: Pro bearer token exposed via apt-helper command line - Write APT credentials to a temporary 0600 auth file and pass a credential-free URL to apt-helper, instead of embedding the token in the download-file URL argument where it leaked to local users via /proc//cmdline. Source tarball re-packed with the fix (3.0 native). - cve-2026-9494 * SECURITY UPDATE: APT source injection via crafted contract-server response - validate contract directives (aptURL, suites, additionalPackages) to reject newline/CR/NUL/space characters, preventing injection of attacker-controlled lines into root-owned apt sources and the apt-get install invocation. Source tarball re-packed with the fix (3.0 native). - cve-2026-11386 * SECURITY UPDATE: symlink file disclosure in "pro collect-logs" - Skip symlinked user log files and create the diagnostic archive exclusively (x:gz) with a root-only umask so an existing output file or symlink is not followed or overwritten. Source tarball re-packed with the fix (3.0 native). - cve-2026-12391
Updated packages:
  • ubuntu-advantage-pro_32.3~18.04+tuxcare.els2_all.deb
    sha:aeeb06b29a1b1379ec86258abf26d60bf87f7e63
  • ubuntu-advantage-tools_32.3~18.04+tuxcare.els2_all.deb
    sha:54498856d5ac21aad75fbdf3711915627cdf218a
  • ubuntu-pro-auto-attach_32.3~18.04+tuxcare.els2_all.deb
    sha:55be1ca572f5a7e55921167a371aa74992b065c0
  • ubuntu-pro-client_32.3~18.04+tuxcare.els2_amd64.deb
    sha:42617bbcd404a94f14dedaf9965ea97ec4f88e3d
  • ubuntu-pro-client-l10n_32.3~18.04+tuxcare.els2_amd64.deb
    sha:f7d374e53af5bd031d546fb4af41374f23c54d6f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.