[CLSA-2026:1786471812] Fix CVE(s): CVE-2026-34180, CVE-2026-42766
Type:
security
Severity:
Important
Release date:
2026-08-11 18:10:25 UTC
Description:
* SECURITY UPDATE: heap buffer over-read parsing large DER ASN.1 elements - debian/patches/openssl-1.1.1-cve-2026-34180.patch: keep the ASN.1 content length as a long in asn1_ex_c2i() and reject elements whose length does not fit in an int, so a primitive element longer than 2GB can no longer be truncated into a negative length and make ASN1_STRING_set() read past the end of the input buffer. - CVE-2026-34180 * SECURITY UPDATE: NULL pointer dereference in password-based CMS decryption - debian/patches/openssl-1.1.1-cve-2026-42766.patch: check that the OPTIONAL PasswordRecipientInfo.keyDerivationAlgorithm field is present before dereferencing it in cms_RecipientInfo_pwri_crypt(), so a crafted password-encrypted CMS message can no longer crash the application. - CVE-2026-42766
Updated packages:
  • alt-openssl11_1.1.1w-3.8_amd64.deb
    sha:3681b40ce4011260c1b3049b5864eff307d33b49
  • alt-openssl11-dev_1.1.1w-3.8_amd64.deb
    sha:04b5d8728a4b0a7fe4ee593e5d08d5b06da8ae1f
  • alt-openssl11-doc_1.1.1w-3.8_all.deb
    sha:4c8890fb0ba8e345f854d5416f8804ccc0744eaa
  • alt-openssl11-libs_1.1.1w-3.8_amd64.deb
    sha:e2f281f9e45c54a5901eadd37733b0b0b2f5de7d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.