[CLSA-2026:1787062482] Fix CVE(s): CVE-2026-38753, CVE-2026-38754
Type:
security
Severity:
Moderate
Release date:
2026-08-18 14:14:55 UTC
Description:
* SECURITY UPDATE: use-after-free in the awk sub()/gsub()/gensub() replacement string - debian/patches/CVE-2026-38753.patch: awk: copy the replacement string before evaluating the regex argument in awk_sub() - CVE-2026-38753 * SECURITY UPDATE: out-of-bounds read in the ash IFS splitting code - debian/patches/CVE-2026-38754.patch: ash: release stale IFS region state when an expansion error is caught in redirectsafe() - CVE-2026-38754
Updated packages:
  • busybox_1.30.1-4+tuxcare.els4_amd64.deb
    sha:3b62e01b41ae44d2ed81ebf9ef452af8af5aa16e
  • busybox-static_1.30.1-4+tuxcare.els4_amd64.deb
    sha:b0bc97bbf1e0d75bb8fe7f88d77b2062f9d5f404
  • busybox-syslogd_1.30.1-4+tuxcare.els4_all.deb
    sha:0d9610d0bbd788f87e2f8a7c10abe7d260373dd9
  • udhcpc_1.30.1-4+tuxcare.els4_amd64.deb
    sha:0d15d15ce5d2852b9b859b2abbe5ddf9094fcced
  • udhcpd_1.30.1-4+tuxcare.els4_amd64.deb
    sha:0833b8442e38fa1f6a74ca0887cbaaabfbfef5fd
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.