[CLSA-2026:1789116242] Fix CVE(s): CVE-2018-6952
Type:
security
Severity:
Important
Release date:
2026-09-11 08:44:12 UTC
Description:
* SECURITY UPDATE: Double free in another_hunk() via pch_swap() - debian/patches/CVE-2018-6952.patch: in pch_swap(), src/pch.c, derive the non-freeable pointer range shift from p_ptrn_lines instead of the already-incremented line index, so p_bfake/p_efake keep bracketing the aliased fill lines after a swap. With a blank line in the middle of a context-diff hunk the range was off by one and the next another_hunk() call freed an aliased line twice - CVE-2018-6952
CVEs fixed:
Updated packages:
  • patch_2.7.6-7+tuxcare.els1_amd64.deb
    sha:6b49b38eaa79925246abaabae55d81ecfff6610d
  • patch_2.7.6-7+tuxcare.els1_arm64.deb
    sha:ba11eaf135f5202fc34bda4b52c006c532aaca4e
  • patch_2.7.6-7+tuxcare.els1_armel.deb
    sha:88522183ea27e331f54477f5ae363318c3fd6306
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.