CLSA-2026-1778489354

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2026-1778489354
Upstream
  • CVE-2026-6100
Published
2026-05-11T08:49:20Z
Modified
2026-06-01T00:33:14.692587545Z
Summary
python2: Fix of CVE-2026-6100
Details
  • CVE-2026-6100: defensively null bzs->nextin on the error path of BZ2Decompdecompress to align with upstream; the UAF window does not exist in Python 2.7 (next_in is reassigned at function entry, lzma/gzip are not C extensions)
References

Affected packages

TuxCare:CentOS-Stream:8
python2

Package

Name
python2
Purl
pkg:rpm/tuxcare/python2?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"
python2-debug

Package

Name
python2-debug
Purl
pkg:rpm/tuxcare/python2-debug?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"
python2-devel

Package

Name
python2-devel
Purl
pkg:rpm/tuxcare/python2-devel?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"
python2-libs

Package

Name
python2-libs
Purl
pkg:rpm/tuxcare/python2-libs?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"
python2-test

Package

Name
python2-test
Purl
pkg:rpm/tuxcare/python2-test?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"
python2-tkinter

Package

Name
python2-tkinter
Purl
pkg:rpm/tuxcare/python2-tkinter?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"
python2-tools

Package

Name
python2-tools
Purl
pkg:rpm/tuxcare/python2-tools?distro=centos-stream-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.18-17.module_el8+2394+f902ce48.tuxcare.els10

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos-stream8els/CLSA-2026-1778489354.json"