icu-67.1-10.el9_6

エラータID: AXSA:2025-10657:01

Release date: 
Thursday, July 31, 2025 - 11:22
Subject: 
icu-67.1-10.el9_6
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
Moderate
Description: 

The International Components for Unicode (ICU) library provides robust and full-featured Unicode services.

Security Fix(es):

* icu: Stack buffer overflow in the SRBRoot::addTag function (CVE-2025-5222)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2025-5222
A stack buffer overflow was found in Internationl components for unicode (ICU ). While running the genrb binary, the 'subtag' struct overflowed at the SRBRoot::addTag function. This issue may lead to memory corruption and local arbitrary code execution.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. icu-67.1-10.el9_6.src.rpm
    MD5: 0c56a8505db73648deaa9ac1ea6a2d17
    SHA-256: 378da40a79cacc5e572db49dd915cd03c1835c4b543fefe005150b7cbf8b0c08
    Size: 22.11 MB

Asianux Server 9 for x86_64
  1. icu-67.1-10.el9_6.x86_64.rpm
    MD5: d5db83c8ba746c526303981161956c6a
    SHA-256: 6155e9cbd86e5d2e73c34d39f8fc2ee2be053e497d28074802ce7593a69e5414
    Size: 233.20 kB
  2. libicu-67.1-10.el9_6.i686.rpm
    MD5: 91932ba72ef77f1ff84f309473f1859c
    SHA-256: b2c69629e60a3dfca5b4f7cd5886d5c92559bd96139c498d0372077cf9ae2c92
    Size: 9.74 MB
  3. libicu-67.1-10.el9_6.x86_64.rpm
    MD5: b85ff4b1152ff902b7f2048948e6d18f
    SHA-256: d7f5353f460067a191097a0ab0ec6640d006acbabf131ec50d960ee7efbbaa80
    Size: 9.57 MB
  4. libicu-devel-67.1-10.el9_6.i686.rpm
    MD5: 28349a8db88608d27bdc7d30fbe581b6
    SHA-256: 40610b2831d1df78e929e20be479c05f0bc864e9a86c32531aea9368e2d11149
    Size: 931.04 kB
  5. libicu-devel-67.1-10.el9_6.x86_64.rpm
    MD5: d446b30df97747678b14e48bf405c336
    SHA-256: 00d3092098bbcafd5bc0ee7a77ef44fe90ae4530176aa2eda15c13bc653ebebc
    Size: 929.80 kB