{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-54874: dtls: buffer only a record's own on-wire bytes in\n  dtls1_buffer_record() instead of taking over the whole read buffer, and lower\n  the next-epoch record queue cap from 100 to 16, so a peer sending tiny\n  next-epoch records can no longer pin ~1.7MB of heap per connection",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012",
        "url": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_common/el10/advisories/2026/clsa-2026_1789647012.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-24T16:48:16Z",
      "generator": {
        "date": "2026-09-24T16:48:16Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789647012",
      "initial_release_date": "2026-09-17T12:10:47Z",
      "revision_history": [
        {
          "date": "2026-09-17T12:10:47Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-09-24T16:48:16Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "alt-openssl11: Fix of CVE-2026-54874"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 10",
                "product": {
                  "name": "Community Enterprise Operating System 10",
                  "product_id": "CentOS-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.8.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.8.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.8.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.6.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.6.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.6.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.5.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.5.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.5.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.4.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.4.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.4.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
                "product": {
                  "name": "alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
                  "product_id": "alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl-libs@1.0.2u-4.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-1:1.0.2u-4.el10.x86_64",
                "product": {
                  "name": "alt-openssl-1:1.0.2u-4.el10.x86_64",
                  "product_id": "alt-openssl-1:1.0.2u-4.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl@1.0.2u-4.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
                "product": {
                  "name": "alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
                  "product_id": "alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl-devel@1.0.2u-4.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.3.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.3.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.3.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.2.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.2.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.2.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
                  "product_id": "alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-libs@1.1.1w-3.1.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
                  "product_id": "alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11-devel@1.1.1w-3.1.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
                "product": {
                  "name": "alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
                  "product_id": "alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-openssl11@1.1.1w-3.1.el10?arch=x86_64&epoch=1&os_name=centos&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.8.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.6.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.5.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.4.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-libs-1:1.0.2u-4.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64"
        },
        "product_reference": "alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-1:1.0.2u-4.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64"
        },
        "product_reference": "alt-openssl-1:1.0.2u-4.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl-devel-1:1.0.2u-4.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64"
        },
        "product_reference": "alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.3.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.2.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64"
        },
        "product_reference": "alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64"
        },
        "product_reference": "alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-openssl11-1:1.1.1w-3.1.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64"
        },
        "product_reference": "alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-54874",
      "cwe": {
        "id": "CWE-405",
        "name": "Asymmetric Resource Consumption (Amplification)"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: Receiving a DTLS record for a future epoch while a handshake\nis in progress causes OpenSSL to buffer far more memory than the record\nitself requires.\n\nImpact summary: A peer can use a small amount of network traffic to make an\nOpenSSL DTLS endpoint retain a disproportionately large amount of memory,\nwhich may lead to a Denial of Service.\n\nCWE: CWE-405: Asymmetric Resource Consumption (Amplification)\n\nDescription: While a DTLS handshake is in progress, a peer may legitimately\nhave already moved on to the next epoch (for example, having sent its\nChangeCipherSpec and Finished messages) before the local endpoint has\nprocessed the same transition, typically because of reordering on the\nunderlying UDP transport. OpenSSL buffers such early records so that they\ncan be processed once the local endpoint catches up.\n\nBuffering a record currently retains the entire read buffer it arrived in,\nwhich is sized to hold the largest possible DTLS record (around 16\nkilobytes), rather than just the bytes that make up the record itself. Up\nto 100 such records may be buffered per connection. As a result, a peer\nthat sends a stream of small forged records claiming to belong to the next\nepoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of\nmemory, despite sending only a small fraction of that amount of data over\nthe network.\n\nAn attacker therefore gains a memory amplification factor of around 1200,\nand can multiply the effect across as many associations as it is able to\nopen, making this a remote memory exhaustion Denial of Service risk for\nDTLS servers. Since the memory retained per connection remains bounded,\nand any limit an application already places on the number of concurrent\nassociations also bounds the total exposure, this issue has been assessed\nas Low severity.\n\nFIPS impact: no\n\nNo FIPS modules are affected by this issue as the affected code is outside\nthe OpenSSL FIPS module boundary.\n\nOpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this\nissue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.2.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.4.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.8.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.7.\nOpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.\n\nPremium support customers only:\nOpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi\nOpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr\n\nThis issue was reported on 18 May 2026 by Amazon Web Services.\nThe fix has been developed by Matt Caswell.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Amazon Web Services\nFixed by: Matt Caswell",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-54874"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23",
          "url": "https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40",
          "url": "https://github.com/openssl/openssl/commit/7110cb2f75806d0bf809eb2f90790d477900be40"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382",
          "url": "https://github.com/openssl/openssl/commit/a0c8ec557d9cac078f032d76cdf684fe743eb382"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107",
          "url": "https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c",
          "url": "https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260825.txt",
          "url": "https://openssl-library.org/news/secadv/20260825.txt"
        }
      ],
      "release_date": "2026-08-25T13:19:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-17T12:10:14.650695Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012",
          "product_ids": [
            "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012"
        },
        {
          "category": "none_available",
          "date": "2026-08-25T13:19:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-7383",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: A signed integer overflow when sizing the destination\nbuffer for Unicode output in ASN1_mbstring_ncopy() can lead to a heap\nbuffer overflow.\n\nImpact summary: A heap buffer overflow may lead to a crash or possibly\nattacker controlled code execution or other undefined behaviour.\n\nIn ASN1_mbstring_copy() and ASN1_mbstring_ncopy() the destination\nsize for Unicode output is computed in a signed int: by left shift\nof the input character count for BMPSTRING (UTF-16) and\nUNIVERSALSTRING (UTF-32), and by summing per-character byte counts\nfor UTF8STRING. The calculation overflows when the input reaches\naround 2^30 characters. In the worst case (UNIVERSALSTRING at 2^30\ncharacters) the size wraps to zero, OPENSSL_malloc(1) is called, and\nthe subsequent character copy writes several gigabytes past the\none-byte allocation.\n\nX.509 certificate processing routes through ASN1_STRING_set_by_NID(),\nwhose DIRSTRING_TYPE mask excludes UNIVERSALSTRING and whose per-NID\nsize limits cap the input length; no network protocol or\ncertificate-handling path in OpenSSL exercises the overflow.\nTriggering the bug requires an application that calls\nASN1_mbstring_copy() or ASN1_mbstring_ncopy() directly, or registers\na custom string type via ASN1_STRING_TABLE_add(), with\nattacker-controlled input on the order of half a gigabyte or more.\nFor these reasons this issue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4 and 3.0 are not affected by\nthis issue, as the affected code is outside the OpenSSL FIPS module\nboundary.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-7383"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6",
          "url": "https://github.com/openssl/openssl/commit/4f8d2bddaa2c8e06f9c33390ee1717059a6e4be6"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74",
          "url": "https://github.com/openssl/openssl/commit/80c15faaf78042bbb8654a0e234c50c381732f74"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974",
          "url": "https://github.com/openssl/openssl/commit/bd17511070fb39a67bfa19682affb765e706a974"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083",
          "url": "https://github.com/openssl/openssl/commit/c332adaced43bcbb85f97410597e951c11ec3083"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255",
          "url": "https://github.com/openssl/openssl/commit/d32350ae8ef7426718f5aa9e383d4b51398ee255"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260609.txt",
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        }
      ],
      "release_date": "2026-06-09T17:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-17T12:10:14.650695Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012",
          "product_ids": [
            "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T17:17:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-9076",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "notes": [
        {
          "category": "description",
          "text": "Issue summary: When CMS password-based decryption (RFC 3211 / PWRI key unwrap)\nprocesses attacker-supplied CMS data, an attacker-chosen stream-mode KEK\ncipher can trigger a heap out-of-bounds read in kek_unwrap_key().\n\nImpact summary: A heap buffer over-read may trigger a crash which leads to\nDenial of Service for an application if the input buffer ends at a memory\npage boundary and the following page is unmapped. There is no information\ndisclosure as the over-read bytes are not revealed to the attacker.\n\nThe key unwrapping function performs a check-byte test as specified in the\nRFC that reads 7 bytes from a heap allocation that is based on the wrapped\nkey length from the message. There is a minimum length check based on the\nblock length of the wrapping cipher. However the cipher is selected from\nan OID carried in the attacker's PWRI keyEncryptionAlgorithm with no\nrequirement that the cipher be a block cipher. When an attacker selects\na stream-mode cipher the guard will be ineffective and the allocated buffer\ncontaining the unwrapped key can be too small to fit the check-bytes\nspecified in the RFC and a buffer over-read can happen.\n\nApplications calling CMS_decrypt() or CMS_decrypt_set1_password()\n(equivalently openssl cms -decrypt -pwri_password ...) on untrusted CMS\ndata are vulnerable to this issue. No password knowledge is required: the\nover-read happens during the unwrap attempt before any authentication\nsucceeds.\n\nThe over-read is limited to a few bytes and is not written to output, so\nthere is no information disclosure. Triggering a crash requires the\nallocation to border unmapped memory, which is unlikely with the normal\nallocator.\n\nThe FIPS modules are not affected by this issue.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
          "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-common/cve/CVE-2026-9076"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb",
          "url": "https://github.com/openssl/openssl/commit/05b066366842f930fadd9a6e94df98030af431bb"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0",
          "url": "https://github.com/openssl/openssl/commit/3d8d5bc1056b2f62da9fede23fedbf47e85187b0"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98",
          "url": "https://github.com/openssl/openssl/commit/715349a1d7c6db970e6815dafb90915f07307f98"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26",
          "url": "https://github.com/openssl/openssl/commit/77bf00ab13f6ff5e516535432f0328ed70ec0c26"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6",
          "url": "https://github.com/openssl/openssl/commit/eecbe330977e8d023aae1ca2d9bdbe983ef3fdc6"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260609.txt",
          "url": "https://openssl-library.org/news/secadv/20260609.txt"
        }
      ],
      "release_date": "2026-06-09T17:17:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-17T12:10:14.650695Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012",
          "product_ids": [
            "CentOS-10:alt-openssl11-1:1.1.1w-3.8.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.8.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.8.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-common/releases/CLSA-2026:1789647012"
        },
        {
          "category": "none_available",
          "date": "2026-06-09T17:17:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-openssl-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-devel-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl-libs-1:1.0.2u-4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-devel-1:1.1.1w-3.6.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.1.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.2.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.3.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.4.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.5.el10.x86_64",
            "CentOS-10:alt-openssl11-libs-1:1.1.1w-3.6.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}