Release date:
2026-08-11 18:06:04 UTC
Description:
- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a
primitive element longer than 2GB can no longer cause a heap buffer over-read
- CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm
is present before dereferencing it, avoiding a NULL pointer dereference
Updated packages:
-
alt-openssl11-1.1.1w-3.6.el7.x86_64.rpm
sha:5872205ec41b06e04cbd2991704bc2e2daab0467326d6ff107471a61071bdcb0
-
alt-openssl11-devel-1.1.1w-3.6.el7.x86_64.rpm
sha:9598f83599950ab3e828f5274181aa30187b784ae8084bfe3ecc08c1978b5982
-
alt-openssl11-libs-1.1.1w-3.6.el7.x86_64.rpm
sha:eb23696373d625421f1004a3144d225d45416cb38687cd785c61e84d939b5bc2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.