Release date:
2026-09-08 22:31:38 UTC
Description:
* SECURITY UPDATE: FCGI demux record length integer overflow
- debian/patches/CVE-2026-55203.patch: widen fcgi_conn.drl from uint16_t
to uint32_t in src/mux_fcgi.c to prevent drl += drp overflow to 0
- CVE-2026-55203
Updated packages:
-
haproxy_2.2.9-2+deb11u7+tuxcare.els2_amd64.deb
sha:6641b6b40e3152a31c63394c98c3a3c490d41f58
-
haproxy-doc_2.2.9-2+deb11u7+tuxcare.els2_all.deb
sha:d4ddc910d8bc7e0229b1caabb65b362c132f48ed
-
vim-haproxy_2.2.9-2+deb11u7+tuxcare.els2_all.deb
sha:0449c62d41e98ac6adcde47e77ed4cd167a5c5d2
-
haproxy_2.2.9-2+deb11u7+tuxcare.els2_arm64.deb
sha:6d2fdce88c537065ac97b3557a73aa95be371f3d
-
haproxy_2.2.9-2+deb11u7+tuxcare.els2_armel.deb
sha:a8630223e18e1bf06c5d0af8e6547c58947e5b8b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.