[CLSA-2026:1786005006] openssl11: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-08-06 14:50:40 UTC
Description:
- CVE-2026-45447: fix use-after-free of a caller-owned BIO in PKCS7_verify() when the SignedData digestAlgorithms field is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:49f1054f79f81cd9665c39232e88ef903d55dd9120db4d1aaefd51c070620829
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:00a127364804cd69d23eb4766d48d9334b7b39381d64becf6866fb9c59b3faab
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:fc2062277d6da6ccdf46702391138837c8c36ce187ffda1cecf26e4313ec51e6
  • openssl11-static-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:83eeceafbb9dcfbd26cdac76717b0b0efed216978d620a0a27d27ad5bcaf1cf5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.