[CLSA-2026:1785918695] alt-openssl11: Fix of CVE-2025-69419
Type:
security
Severity:
Important
Release date:
2026-08-05 08:31:47 UTC
Description:
- HollowByte: grow the handshake init_buf incrementally as data is received instead of pre-allocating the full peer-declared message size, so a peer that claims a large message but never sends it can no longer strand memory (ELS-2635). Backport of OpenSSL 3.0 commit c5785a5e35 (PR #30794); handled by OpenSSL as a "bug or hardening" fix with no CVE assigned
CVEs fixed:
Updated packages:
  • alt-openssl11-1.1.1w-3.5.el10.x86_64.rpm
    sha:fe68d6537d06a46e598deaa54d74d076cf75be4bdfe9265b9d95aac1c652eeb1
  • alt-openssl11-devel-1.1.1w-3.5.el10.x86_64.rpm
    sha:e1a7cdd65556b6436cc58a3d9c3118873b11fea594f0698957cb910de13a3b48
  • alt-openssl11-libs-1.1.1w-3.5.el10.x86_64.rpm
    sha:308fc3ec08f9bd9b3fdcf266812534d89215b1949cbf41a1f39aa727346604bc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.