[CLSA-2026:1787064466] Fix CVE(s): CVE-2026-40176, CVE-2026-40261
Type:
security
Severity:
Important
Release date:
2026-08-18 14:47:57 UTC
Description:
* Non-maintainer upload by the TuxCare ELS team. * CVE-2026-40261: Prevent a command injection vulnerability in Perforce::syncCodeBase(), which appended the source reference to the 'p4 sync -f' command without escaping. Package metadata served by a malicious or compromised Composer repository could inject shell metacharacters, leading to command execution even when Perforce is not installed. - debian/patches/0018-CVE-2026-40261.patch * CVE-2026-40176: Prevent a command injection vulnerability in Perforce::generateP4Command(), which interpolated the Perforce connection parameters (user, client, port) into the 'p4' command line without escaping. A malicious composer.json declaring a Perforce VCS repository could inject shell metacharacters, leading to command execution even when Perforce is not installed. Also backport the prerequisite upstream fix for Perforce::connectClient(), which passed the client spec path through the shell redirection of the same command line with only spaces escaped. - debian/patches/0019-CVE-2026-40176.patch
Updated packages:
  • composer_1.8.4-1+deb10u4+tuxcare.els1_all.deb
    sha:8a4cc08e4fa3b5b6b4284a4fd2a9183b375028f0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.