[CLSA-2026:1790932709] mutt: Fix of 8 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-10-02 09:19:10 UTC
Description:
- Add Alma9_8ESU; carry the tuxcare9.6esu CVE fixes - CVE-2024-49394: protect In-Reply-To and References under the cryptographic signature (add to protected headers) - CVE-2024-49395: fix missing display of encryption recipients in GPGME - CVE-2026-43859: use memcpy() instead of strfcpy() in hmac_md5() so a binary MD5 digest of an over-long IMAP CRAM-MD5 secret is not truncated at an embedded NUL - CVE-2026-43860: copy the full MD5_DIGEST_LEN bytes of the hashed IMAP CRAM-MD5 secret in hmac_md5() instead of one byte less - CVE-2026-43861: reject a percent-encoded NUL (%00) as an invalid character in url_pct_decode() - CVE-2026-43862: check that the GSSAPI security-level token is at least 4 bytes before reading it in imap_auth_gss(), and read it as uint32_t - CVE-2026-43863: treat a negative gpgme_data_read() return as an error in data_object_to_stream() instead of looping forever - CVE-2026-43864: check key and key->subkeys for NULL in show_sig_summary()
Updated packages:
  • mutt-2.2.6-2.el9.tuxcare.els4.aarch64.rpm
    sha:3e7165aecedf6d5bd56ee0364aae0bdfadbf6ad5a64a25f6257915c63938cef9
  • mutt-2.2.6-2.el9.tuxcare.els4.i686.rpm
    sha:415e1db058598419a313c334c9d1da3a4d4dd65d6a3616926276e053406a9881
  • mutt-2.2.6-2.el9.tuxcare.els4.x86_64.rpm
    sha:486b5c5215580b4fc1de6cc25b678d76f9dc50ab71342610ea77c787fac075c2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.