Release date:
2026-08-05 09:38:48 UTC
Description:
* SECURITY UPDATE: HollowByte handshake-buffer pre-allocation DoS
- debian/patches/openssl-1.1.1-hollowbyte.patch: grow the handshake
init_buf incrementally as data is received instead of pre-allocating
the full peer-declared message size, so a peer that claims a large
message but never sends it can no longer strand memory. Backport of
OpenSSL 3.0 commit c5785a5e35 (PR #30794). OpenSSL handled this as a
"bug or hardening" fix, so no CVE was assigned.
- ELS-2635
Updated packages:
-
alt-openssl11_1.1.1w-3.7_amd64.deb
sha:00612d5bcd72ec823a238b3bae3dae706e25195c
-
alt-openssl11-dev_1.1.1w-3.7_amd64.deb
sha:ea9be808e1828a5b4de6d72b89f1f3cbdf4d0eb4
-
alt-openssl11-doc_1.1.1w-3.7_all.deb
sha:1cc1ec75d7ba14bf5ac8c3dc71f49cde1777528d
-
alt-openssl11-libs_1.1.1w-3.7_amd64.deb
sha:6ba21143082edc4a6d477ddefd593fa75c256bd0
-
alt-openssl11_1.1.1w-3.7_arm64.deb
sha:03c5d884cd44f4d78e2907f8c1b307e348db791f
-
alt-openssl11-dev_1.1.1w-3.7_arm64.deb
sha:267e2813f857308fe45f15d9ad7f4ab107b5318b
-
alt-openssl11-doc_1.1.1w-3.7_all.deb
sha:1cc1ec75d7ba14bf5ac8c3dc71f49cde1777528d
-
alt-openssl11-libs_1.1.1w-3.7_arm64.deb
sha:96e1d16378e72a289eae4c5dd89b2665c05c3155
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.