[CLSA-2026:1786006093] openssl11: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-08-06 08:48:23 UTC
Description:
- CVE-2026-45447: fix use-after-free of a caller-owned BIO in PKCS7_verify() when the SignedData digestAlgorithms field is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:cda2640b1835efd99816b4d774916fd9d7c7d15e7412d6a454256dce186cf406
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:9205cd033555c74eec871d416f2edc9287ee061ea88e8f1f43f4a64cbea34302
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:640a6a44be4742f9803f5ece19c9816edf1e75f8208aac75962124288a7c0f65
  • openssl11-static-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:fb5e4944ea849fb954451f3c0f3b3588f17df63fd76c06681037ad36750247c1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.