[CLSA-2026:1787732137] Fix CVE(s): CVE-2023-3297
Type:
security
Severity:
Important
Release date:
2026-08-26 08:15:51 UTC
Description:
* SECURITY UPDATE: use-after-free in user.c (LP: #2024182) - debian/patches/CVE-2023-3297.patch: return from user_change_language_authorized_cb() and user_change_formats_locale_authorized_cb() after throw_error() has consumed the D-Bus invocation, instead of falling through to accounts_user_complete_set_language()/set_formats_locale() and completing the freed invocation a second time. - CVE-2023-3297
CVEs fixed:
Updated packages:
  • accountsservice_0.6.45-1ubuntu1.3+tuxcare.els1_amd64.deb
    sha:f41414c532388f1b1b76a0600fae7a478128a426
  • gir1.2-accountsservice-1.0_0.6.45-1ubuntu1.3+tuxcare.els1_amd64.deb
    sha:29e5a8a18b0256943c5e3df8a2e1dddab2fe7795
  • libaccountsservice-dev_0.6.45-1ubuntu1.3+tuxcare.els1_amd64.deb
    sha:b4ba0580589b06c74b278fee673430ac111f4ffa
  • libaccountsservice-doc_0.6.45-1ubuntu1.3+tuxcare.els1_all.deb
    sha:5318aea2d51dafc258a124f47f2334e23f772e79
  • libaccountsservice0_0.6.45-1ubuntu1.3+tuxcare.els1_amd64.deb
    sha:8295ad945969c89fdcfbda036c718a3bdb13cfa7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.