Release date:
2026-08-11 18:34:02 UTC
Description:
* SECURITY UPDATE: heap buffer over-read parsing large DER ASN.1 elements
- debian/patches/openssl-1.1.1-cve-2026-34180.patch: keep the ASN.1
content length as a long in asn1_ex_c2i() and reject elements whose
length does not fit in an int, so a primitive element longer than
2GB can no longer be truncated into a negative length and make
ASN1_STRING_set() read past the end of the input buffer.
- CVE-2026-34180
* SECURITY UPDATE: NULL pointer dereference in password-based CMS decryption
- debian/patches/openssl-1.1.1-cve-2026-42766.patch: check that the
OPTIONAL PasswordRecipientInfo.keyDerivationAlgorithm field is present
before dereferencing it in cms_RecipientInfo_pwri_crypt(), so a crafted
password-encrypted CMS message can no longer crash the application.
- CVE-2026-42766
Updated packages:
-
alt-openssl11_1.1.1w-3.8_amd64.deb
sha:137dc54e95c3c3f9893027f0bc7995589d3619e8
-
alt-openssl11-dev_1.1.1w-3.8_amd64.deb
sha:678dd830dc14bd0e8366fe41bddd47bb905b5525
-
alt-openssl11-doc_1.1.1w-3.8_all.deb
sha:4c8890fb0ba8e345f854d5416f8804ccc0744eaa
-
alt-openssl11-libs_1.1.1w-3.8_amd64.deb
sha:6e8c2e18ccb7bce94b0789c7172fee0d2cad022a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.