[CLSA-2026:1788258008] bzip2: Fix of CVE-2019-12900
Type:
security
Severity:
Critical
Release date:
2026-09-01 10:20:19 UTC
Description:
- CVE-2019-12900: fix out-of-bounds write in BZ2_decompress when many selectors are present - CVE-2016-3189: fix use-after-free in bzip2recover
CVEs fixed:
Updated packages:
  • bzip2-1.0.6-13.amzn2.0.3.tuxcare.els1.x86_64.rpm
    sha:45553f0f01d657f938079090b85395fc3725c0956812465edd967d0fd6dd959d
  • bzip2-devel-1.0.6-13.amzn2.0.3.tuxcare.els1.x86_64.rpm
    sha:a88bfa378b7085d5ba828c61b7f4f0497830704e09ca1e776324184ece7a633c
  • bzip2-libs-1.0.6-13.amzn2.0.3.tuxcare.els1.i686.rpm
    sha:7d1904c21430942d238170b1f53c31927226632db9a73a86bc518b9a2fd66bf8
  • bzip2-libs-1.0.6-13.amzn2.0.3.tuxcare.els1.x86_64.rpm
    sha:467bad4e0c3ece9e82e7c2d56c2927ed6dbec330b4d0ac744937541d7eb77772
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.