Release date:
2026-09-11 08:44:12 UTC
Description:
* SECURITY UPDATE: Double free in another_hunk() via pch_swap()
- debian/patches/CVE-2018-6952.patch: in pch_swap(), src/pch.c, derive
the non-freeable pointer range shift from p_ptrn_lines instead of the
already-incremented line index, so p_bfake/p_efake keep bracketing the
aliased fill lines after a swap. With a blank line in the middle of a
context-diff hunk the range was off by one and the next
another_hunk() call freed an aliased line twice
- CVE-2018-6952
Updated packages:
-
patch_2.7.6-7+tuxcare.els1_amd64.deb
sha:6b49b38eaa79925246abaabae55d81ecfff6610d
-
patch_2.7.6-7+tuxcare.els1_arm64.deb
sha:ba11eaf135f5202fc34bda4b52c006c532aaca4e
-
patch_2.7.6-7+tuxcare.els1_armel.deb
sha:88522183ea27e331f54477f5ae363318c3fd6306
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.