[CLSA-2026:1788177078] coreutils: Fix of CVE-2026-56392
Type:
security
Severity:
Moderate
Release date:
2026-08-31 11:51:29 UTC
Description:
- CVE-2026-56392: fix heap buffer overflow in unexpand caused by an integer overflow when allocating the pending-blank buffer for large -t values (backport of upstream b60a159f and follow-up 4ade9cf7)
CVEs fixed:
Updated packages:
  • coreutils-8.32-39.el9.tuxcare.els2.x86_64.rpm
    sha:a714925f97e8ffa352ac33f2728afde5a0ac624bf93a00dd08f75c0fdd28c370
  • coreutils-common-8.32-39.el9.tuxcare.els2.x86_64.rpm
    sha:68b3fb493d211ac8b6d1fe9c176999fecb49c5cf9edf7c6c2249e2313edc1128
  • coreutils-single-8.32-39.el9.tuxcare.els2.x86_64.rpm
    sha:107958fb0ba532b5f7094175b5f934f1f78ad07c7af07bd1bdf0908eb8fc4738
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.