[CLSA-2026:1789671837] Fix CVE(s): CVE-2026-59885, CVE-2026-59886
Type:
security
Severity:
Important
Release date:
2026-09-17 19:04:10 UTC
Description:
* SECURITY UPDATE: Quadratic complexity in OBJECT IDENTIFIER decoding - debian/patches/CVE-2026-59885.patch: accumulate arcs in a list instead of repeated tuple concatenation in the BER decoder and encoder - CVE-2026-59885 * SECURITY UPDATE: Uncontrolled resource consumption converting univ.Real - debian/patches/CVE-2026-59886.patch: use math.ldexp for base 2 and reject base-10 exponents above sys.float_info.max_10_exp in Real.__float__, instead of exact big-integer exponentiation - CVE-2026-59886
Updated packages:
  • pypy-pyasn1_0.4.8-1+deb11u2+tuxcare.els1_all.deb
    sha:017ca97cdb0a4e94cbf6b5c40aca36448989c57c
  • python-pyasn1-doc_0.4.8-1+deb11u2+tuxcare.els1_all.deb
    sha:f16abd8e63ca26e0cd16004c9ec49ee2c649e436
  • python3-pyasn1_0.4.8-1+deb11u2+tuxcare.els1_all.deb
    sha:49f6bd8be290817fbc7acfc6e0f19b79e8d6a5c2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.