[CLSA-2026:1787152014] Fix CVE(s): CVE-2025-5222
Type:
security
Severity:
Important
Release date:
2026-08-19 15:07:05 UTC
Description:
* SECURITY UPDATE: stack buffer overflow in the genrb resource-bundle compiler - debian/patches/CVE-2025-5222.patch: replace the fixed-size 1024-byte subtag/typeKeyword stack buffers in addCollation(), parseCollationElements() and realParseTable() with CharString in source/tools/genrb/parse.cpp, and add the CharString UChar* overload it needs to source/common/charstr.{cpp,h}. - CVE-2025-5222
CVEs fixed:
Updated packages:
  • icu-devtools_60.2-3ubuntu3.2+tuxcare.els1_amd64.deb
    sha:00062101b3041a24d5072f225c19fa560af7a685
  • icu-doc_60.2-3ubuntu3.2+tuxcare.els1_all.deb
    sha:c5b4109f4a475d787bc1da104902c04a0689c634
  • libicu-dev_60.2-3ubuntu3.2+tuxcare.els1_amd64.deb
    sha:f1c254449d15fe9ea58d8bf019ee4ab1a570ba40
  • libicu60_60.2-3ubuntu3.2+tuxcare.els1_amd64.deb
    sha:1cb56d58047f9db01c428ab3dd5f9ed1e795de2a
  • libiculx60_60.2-3ubuntu3.2+tuxcare.els1_amd64.deb
    sha:8d1dc48f652c662e9d86f351201819e326a98672
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.