[CLSA-2026:1785489462] openssl: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-31 16:11:46 UTC
Description:
- CVE-2026-34180: fix heap buffer over-read in ASN.1 content parsing caused by truncating a long content length to int - CVE-2026-7383: fix heap buffer overflow in ASN1_mbstring_ncopy() caused by signed integer overflow when computing the output length - CVE-2026-42766: fix NULL pointer dereference when keyDerivationAlgorithm is absent in CMS PasswordRecipientInfo - CVE-2026-9076: fix out-of-bounds read in kek_unwrap_key() check-byte validation for KEK ciphers with a block size below 4 octets - CVE-2026-42768: enforce implicit rejection for CMS and PKCS#7 RSA PKCS#1 v1.5 decryption
Updated packages:
  • openssl-1.1.1g-15.el8_4.tuxcare.els21.x86_64.rpm
    sha:99ceac18b518f28c85c023ed989471371309370e02d517d6d78db744925a8075
  • openssl-devel-1.1.1g-15.el8_4.tuxcare.els21.i686.rpm
    sha:d41fbf381e1136a83ba40d733ef68287e600c7a8e9217a5b56f9b96ad71bf3ff
  • openssl-devel-1.1.1g-15.el8_4.tuxcare.els21.x86_64.rpm
    sha:23852116ff2d7feb07cf4d7c79f69f4e8aab7aa170ca52529b6cb77a68161796
  • openssl-libs-1.1.1g-15.el8_4.tuxcare.els21.i686.rpm
    sha:57e19ad4e0c435fb54872c0d0b13c1fbd09c6949354d8ffd3ef337a2a95cf21f
  • openssl-libs-1.1.1g-15.el8_4.tuxcare.els21.x86_64.rpm
    sha:4317007a4c05ebbd3a9641c6ffb2e6a08d9884555fdbb8dc1622934ea5198f2f
  • openssl-perl-1.1.1g-15.el8_4.tuxcare.els21.x86_64.rpm
    sha:c530455c0fe8e22d266d775d27c63e509657c73e0464d06a0e97d619c8cb5f60
  • openssl-static-1.1.1g-15.el8_4.tuxcare.els21.x86_64.rpm
    sha:a2694bdf1607abe6134cd193eabe5339939d66dfff314483887377ec42900bde
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.