[CLSA-2026:1786474088] alt-openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-11 18:48:23 UTC
Description:
- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a primitive element longer than 2GB can no longer cause a heap buffer over-read - CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm is present before dereferencing it, avoiding a NULL pointer dereference
Updated packages:
  • alt-openssl11-1.1.1w-3.6.el10.x86_64.rpm
    sha:87c67375ea6b972571b9012b773bf085c7843356318068466dd70f341d6bf713
  • alt-openssl11-devel-1.1.1w-3.6.el10.x86_64.rpm
    sha:582c1c2b02a81ac85ac3c1a01f599cdcf31aa30da340dff3b095e70777f82eff
  • alt-openssl11-libs-1.1.1w-3.6.el10.x86_64.rpm
    sha:ef2d056f912db1e8372c5660d813820206c45f97972a6d934320dbe2fb2e372d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.