[CLSA-2026:1784715933] Fix CVE(s): CVE-2026-25646
Type:
security
Severity:
Important
Release date:
2026-07-22 10:25:59 UTC
Description:
* SECURITY UPDATE: enforce fixed libpng at runtime for CVE-2026-25646 - debian/control: pin openjdk-8-jre Depends on libpng16-16 (>= 1.6.37-2+tuxcare.els2); libsplashscreen dynamically links the system libpng, so the ELS libpng1.6 rebuild carrying the png_set_quantize heap-overflow fix must be present at install time - CVE-2026-25646 * Ref: ELSCVE-134720
CVEs fixed:
Updated packages:
  • openjdk-8-demo_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_amd64.deb
    sha:fe717569211eaec476dc513d254c31c03fde0bb5
  • openjdk-8-doc_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_all.deb
    sha:3a1fa10f8eed5d1f5a7534d9dc3999a9c08c7952
  • openjdk-8-jdk_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_amd64.deb
    sha:8df76459ca51d4b628ed7a97ffe55ec5c6adbcfc
  • openjdk-8-jdk-headless_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_amd64.deb
    sha:c4fff6d15be472503a38338faf03282dd393d109
  • openjdk-8-jre_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_amd64.deb
    sha:bfb7348df23d0d6c21b72981bac17333c45a24c9
  • openjdk-8-jre-headless_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_amd64.deb
    sha:3007a7ad79f379e50f2d15d9350beaa7ee29b9c0
  • openjdk-8-jre-zero_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_amd64.deb
    sha:83f0eeafcc9881de871f6568e496c36e78f2bcc6
  • openjdk-8-source_8u492-ga~us2-0ubuntu1~20.04+tuxcare.els2_all.deb
    sha:16f20a6fb708907659865e7a49357ed1cf89fe46
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.