Description:
SquashFS is a highly compressed read-only file system for Linux. These packages contain the utilities for manipulating squashfs file systems.
Security Fix(es):
* squashfs-tools: unvalidated filepaths allow writing outside of destination (CVE-2021-40153)
* squashfs-tools: possible Directory Traversal via symbolic link (CVE-2021-41072)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.
Updated packages listed below:
Architecture |
Package |
Checksum |
aarch64 |
squashfs-tools-4.3-21.el8.aarch64.rpm |
8d3733337bf4cacf40122ad852144562e9211fc3ca6ce484c7cc06a83f4e48eb |
ppc64le |
squashfs-tools-4.3-21.el8.ppc64le.rpm |
3dfb16bb14507a2ae2ff3a0c781f15fb7dfde81a8b320e5db61ac94e5469715a |
s390x |
squashfs-tools-4.3-21.el8.s390x.rpm |
eaa1ea23e95ce7966b57b9e621a4db9051e6b3d419227082386cc1ae64dd3ac5 |
x86_64 |
squashfs-tools-4.3-21.el8.x86_64.rpm |
ac3ea5d7e8aee48462c30ef9ba9d04e9a5d8326195f4ad1480e549c8ef0a97e2 |