[CLSA-2026:1786545312] openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 14:35:33 UTC
Description:
- CVE-2026-34180: avoid truncating a long ASN.1 content length to int in asn1_ex_c2i(), which caused a heap buffer over-read for primitive elements larger than 2GB - CVE-2026-42766: reject a CMS PasswordRecipientInfo whose keyDerivationAlgorithm is absent instead of dereferencing NULL
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:5f6c5bb817e207822bcefd7165cd6a4d3aa1c6e3415ff1907e76695edc10052a
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:ddac6b3a397906aff3a46513a0a187ab75ed125255bdb751e5709b192b666260
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:9236d6a49946cc0a2ccbfe88b298a3a5972a84dd9eb3d215a0798f509e4fd4d0
  • openssl11-static-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:21a527d55181047ead51088f97d8ccf53474e356bda5d1309eadca5a19cacac9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.