[ALSA-2026:79122] Important: cjose security update
Type:
security
Severity:
important
Release date:
2026-10-09
Description:
CJose is C library implementing the Javascript Object Signing and Encryption (JOSE). Security Fix(es): * cjose: cjose: Heap buffer overflow in AES Key Wrap decryption leads to denial of service (CVE-2026-53938) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 cjose-0.6.2.2-7.el10_2.1.aarch64.rpm 9afff3b2fe86ddc817c6b170ba5ede51c50e0bcca830656ac6b3e544ccdba3b1
aarch64 cjose-devel-0.6.2.2-7.el10_2.1.aarch64.rpm bded22e206dcfd6403fa629e7b916f11cb45329af30717fb951ded00c209f13c
ppc64le cjose-0.6.2.2-7.el10_2.1.ppc64le.rpm 792e4529f69d0473b2d673bd5d4d76252d2b23513f4bf5b604e7c3470feddef8
ppc64le cjose-devel-0.6.2.2-7.el10_2.1.ppc64le.rpm ff4dae3fe0fbbb99113398aa0c5a60997b4aa7610b105cf93ff088a63d66e337
s390x cjose-0.6.2.2-7.el10_2.1.s390x.rpm 088c4fc5ebedcd129e06937b1c173f3c4c9ce6f09e0c61d72c35646dec663188
s390x cjose-devel-0.6.2.2-7.el10_2.1.s390x.rpm 2b5c7aaba838e6aee9a40640473d90d116b9af576778a1a9a463d26476b5c90a
x86_64 cjose-0.6.2.2-7.el10_2.1.x86_64.rpm d6fcaf92389d5517fad8283ab0bf2b0f7edc6ce999b285975d0d06a1a40e8117
x86_64 cjose-devel-0.6.2.2-7.el10_2.1.x86_64.rpm eb7cf912547fe66c4ec3417649807e24eeab86018fc9482d2da8b13c696f15b7
x86_64_v2 cjose-devel-0.6.2.2-7.el10_2.1.x86_64_v2.rpm 3181a3b76c49f38da6187166c1fcbd204c9f43853c64e1e714c6e88626b4ddba
x86_64_v2 cjose-0.6.2.2-7.el10_2.1.x86_64_v2.rpm fc2c70f31e9ec6adf26d68e25e851edc806681dca6049df927577ca8e3586d88
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.