[CLSA-2026:1785921264] alt-openssl11: Fix of CVE-2025-69419
Type:
security
Severity:
Important
Release date:
2026-08-05 09:14:38 UTC
Description:
- HollowByte: grow the handshake init_buf incrementally as data is received instead of pre-allocating the full peer-declared message size, so a peer that claims a large message but never sends it can no longer strand memory (ELS-2635). Backport of OpenSSL 3.0 commit c5785a5e35 (PR #30794); handled by OpenSSL as a "bug or hardening" fix with no CVE assigned
CVEs fixed:
Updated packages:
  • alt-openssl11-1.1.1w-3.5.el8.x86_64.rpm
    sha:17213878bfc795a16b5caf93510bf95c85f1c83f1ec47384cf01c5c146bfb290
  • alt-openssl11-devel-1.1.1w-3.5.el8.x86_64.rpm
    sha:35366d9752d1457858e6257e3645c94e208ca846d3be95e39cb6049854d4cecd
  • alt-openssl11-libs-1.1.1w-3.5.el8.x86_64.rpm
    sha:d64f394087683a770982bc1194906214f2d5baed18ac15ce0eb0e6e7f842f092
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.