[CLSA-2026:1786473823] alt-openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-11 18:43:56 UTC
Description:
- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a primitive element longer than 2GB can no longer cause a heap buffer over-read - CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm is present before dereferencing it, avoiding a NULL pointer dereference
Updated packages:
  • alt-openssl11-1.1.1w-3.6.el9.x86_64.rpm
    sha:8c52a8b640df3c4c0d585835c792a186d26bf915ed3e13e89ad7d1db444d27fc
  • alt-openssl11-devel-1.1.1w-3.6.el9.x86_64.rpm
    sha:32ac0aba7f2562e263a4827e2403b6c917b92c74c9b6fda117ae0af477c1c22f
  • alt-openssl11-libs-1.1.1w-3.6.el9.x86_64.rpm
    sha:443f8419d9646b5f27ed5e660fd56db26da836a9c5b4960362e90ffbdc3a851f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.