[CLSA-2026:1786005591] openssl11: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-08-06 14:38:54 UTC
Description:
- CVE-2026-45447: fix use-after-free of a caller-owned BIO in PKCS7_verify() when the SignedData digestAlgorithms field is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:2b6e24fdde4e815dd6b8f11215222989de8f1ec8733243c4a3e92108c6510360
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:f7b5d527205151fd7dc9429c2211a716ff5078ec09991dd1788f4c8bf78477a2
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:3f38794b53f4aeed7d149781815b6cf6313840b2d52bc869e88225da130a2711
  • openssl11-static-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:fa502faaa88d6cd78769700d24b254e63fd7b52e87d81a9263277aec1d7d3a45
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.