[CLSA-2026:1786471552] alt-openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-11 18:06:04 UTC
Description:
- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a primitive element longer than 2GB can no longer cause a heap buffer over-read - CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm is present before dereferencing it, avoiding a NULL pointer dereference
Updated packages:
  • alt-openssl11-1.1.1w-3.6.el7.x86_64.rpm
    sha:5872205ec41b06e04cbd2991704bc2e2daab0467326d6ff107471a61071bdcb0
  • alt-openssl11-devel-1.1.1w-3.6.el7.x86_64.rpm
    sha:9598f83599950ab3e828f5274181aa30187b784ae8084bfe3ecc08c1978b5982
  • alt-openssl11-libs-1.1.1w-3.6.el7.x86_64.rpm
    sha:eb23696373d625421f1004a3144d225d45416cb38687cd785c61e84d939b5bc2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.