[CLSA-2026:1786493710] openssl: Fix of CVE-2026-31789
Type:
security
Severity:
Critical
Release date:
2026-08-13 05:13:52 UTC
Description:
- CVE-2026-31789: guard against size_t overflow in buf2hexstr_sep / ossl_buf2hexstr_sep (crypto/o_str.c) when hex-printing a huge OCTET STRING; prevents a 32-bit heap overflow. Backport upstream a91e537d
CVEs fixed:
Updated packages:
  • openssl-3.2.2-7.el9_6.tuxcare.1.els8.x86_64.rpm
    sha:bf3e4ecab82d221e738aaa79210b84c829bbe8fb78ade4198cc05c165c99358c
  • openssl-devel-3.2.2-7.el9_6.tuxcare.1.els8.i686.rpm
    sha:45b7c2b7abff15419fd604c7d6783ef76c99463561e41c1dff3e66108665a70a
  • openssl-devel-3.2.2-7.el9_6.tuxcare.1.els8.x86_64.rpm
    sha:b53510ba39ddb3f1dc39803d199883eb357519471b306b69d4478983dcb790a1
  • openssl-libs-3.2.2-7.el9_6.tuxcare.1.els8.i686.rpm
    sha:6125c3f86d3acadb4122c25bb33ebebd7b7201451b529b666e198ddf72edfa8b
  • openssl-libs-3.2.2-7.el9_6.tuxcare.1.els8.x86_64.rpm
    sha:73ecbe52c6a0dcedc3410de72d1429a546c2027b242ef375cffd9eaf0384d15c
  • openssl-perl-3.2.2-7.el9_6.tuxcare.1.els8.x86_64.rpm
    sha:ad732102634b137c37363c891832dead82aa44510870d646a70f0233c5cd575d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.