[CLSA-2026:1785919103] alt-openssl11: Fix of CVE-2025-69419
Type:
security
Severity:
Important
Release date:
2026-08-05 08:38:37 UTC
Description:
- HollowByte: grow the handshake init_buf incrementally as data is received instead of pre-allocating the full peer-declared message size, so a peer that claims a large message but never sends it can no longer strand memory (ELS-2635). Backport of OpenSSL 3.0 commit c5785a5e35 (PR #30794); handled by OpenSSL as a "bug or hardening" fix with no CVE assigned
CVEs fixed:
Updated packages:
  • alt-openssl11-1.1.1w-3.5.el7.x86_64.rpm
    sha:8f749be3d7753243f1c64cda563c04f7d2e5e8c5fc6dee21ef4eb9d70c74ae3e
  • alt-openssl11-devel-1.1.1w-3.5.el7.x86_64.rpm
    sha:340edaef72c6c8c5e0217c3f8e6398ca4245cf4d9ab22e78fd56d4340fbc5e93
  • alt-openssl11-libs-1.1.1w-3.5.el7.x86_64.rpm
    sha:8d0486f7a9a7f32987d3bfa25da29e383182152ed51c294cb603625f37c648f3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.