[CLSA-2026:1787666659] Fix CVE(s): CVE-2026-43958
Type:
security
Severity:
Important
Release date:
2026-08-25 14:04:31 UTC
Description:
* SECURITY UPDATE: stack-based buffer overflow in rrdcached CREATE request handling - debian/patches/CVE-2026-43958.patch: bound the av[] argument array in handle_request_create() so an oversized CREATE request with more than 128 DS:/RRA: definitions can no longer overflow the stack buffer, plus the accompanying upstream hardening in rrd_xport, rrd_graph, rrd_graph_helper and rrd_daemon. The rrd_xport fill loop uses the index-based bounds check from upstream follow-up a8174e6a rather than the timestamp comparison it originally shipped with. - CVE-2026-43958
CVEs fixed:
Updated packages:
  • liblua5.1-rrd-dev_1.5.5-4+tuxcare.els1_all.deb
    sha:a0b288d7e1a42229c431ad5d222052dceacbdf76
  • liblua5.1-rrd0_1.5.5-4+tuxcare.els1_all.deb
    sha:e393c12ae7f45c22ea2d98c986d4688c0449ecb3
  • librrd-dev_1.5.5-4+tuxcare.els1_amd64.deb
    sha:1c8b65212af2d49f017b9d797c1ad83127cf120d
  • librrd4_1.5.5-4+tuxcare.els1_amd64.deb
    sha:939560aae4844ba60fa0d4ffd021ac14a6e6ae85
  • librrdp-perl_1.5.5-4+tuxcare.els1_all.deb
    sha:1d06d66607ab094267bcdf9c0641580cc24d8f30
  • librrds-perl_1.5.5-4+tuxcare.els1_amd64.deb
    sha:eae253394ee7e80606241c441ed1cfc87ea349d7
  • lua-rrd_1.5.5-4+tuxcare.els1_amd64.deb
    sha:a54cee8dc3de4efbe46c36d56c3e2ae93c78b914
  • lua-rrd-dev_1.5.5-4+tuxcare.els1_amd64.deb
    sha:a8552752940dc7ebe04a02d480cc063ace5b91db
  • python-rrdtool_1.5.5-4+tuxcare.els1_amd64.deb
    sha:f152e656e6660670583962869b5820d96537eb1f
  • rrdcached_1.5.5-4+tuxcare.els1_amd64.deb
    sha:9657d444e158f3c28c8032c03217fc512f6f42e8
  • rrdtool_1.5.5-4+tuxcare.els1_amd64.deb
    sha:c1fae118ead5dbaa54760ba9a88a1d9dd04684aa
  • rrdtool-tcl_1.5.5-4+tuxcare.els1_amd64.deb
    sha:6778d5fd13d7b55dc9017f7b75fd1a63569f99cb
  • ruby-rrd_1.5.5-4+tuxcare.els1_amd64.deb
    sha:be4696cfb42ebea22051696f704002aef3cf6b1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.