[CLSA-2026:1786544972] openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 14:29:45 UTC
Description:
- CVE-2026-34180: avoid truncating a long ASN.1 content length to int in asn1_ex_c2i(), which caused a heap buffer over-read for primitive elements larger than 2GB - CVE-2026-42766: reject a CMS PasswordRecipientInfo whose keyDerivationAlgorithm is absent instead of dereferencing NULL
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:0db9cd59ad14d0828c5c18bef1e5aa0e5b243fafc33634b404aff9ec4110da48
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:01944963c6b10b8e1943ff5168b5bc3a7707909b1af2677e0fec6f6c47329f9d
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:93854941980ebd0857910393ec907d82354a4e5ffc80a6b6a9acb49d04c395d8
  • openssl11-static-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:19d1b67023b0ee476081276ee7557ffe861e858e3171a22a96f85653cc257c89
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.