[CLSA-2026:1785922475] Fix CVE(s): CVE-2025-69419
Type:
security
Severity:
Important
Release date:
2026-08-05 09:34:49 UTC
Description:
* SECURITY UPDATE: HollowByte handshake-buffer pre-allocation DoS - debian/patches/openssl-1.1.1-hollowbyte.patch: grow the handshake init_buf incrementally as data is received instead of pre-allocating the full peer-declared message size, so a peer that claims a large message but never sends it can no longer strand memory. Backport of OpenSSL 3.0 commit c5785a5e35 (PR #30794). OpenSSL handled this as a "bug or hardening" fix, so no CVE was assigned. - ELS-2635
CVEs fixed:
Updated packages:
  • alt-openssl11_1.1.1w-3.7_amd64.deb
    sha:3e4d55c4e09343864cdc796155e0457ef4a27898
  • alt-openssl11-dev_1.1.1w-3.7_amd64.deb
    sha:af549a39afa93ec98d841d8fdde238022c762c01
  • alt-openssl11-doc_1.1.1w-3.7_all.deb
    sha:1cc1ec75d7ba14bf5ac8c3dc71f49cde1777528d
  • alt-openssl11-libs_1.1.1w-3.7_amd64.deb
    sha:2ea513cc88a7ee1b30ce040fdf51ec3e58309465
  • alt-openssl11_1.1.1w-3.7_arm64.deb
    sha:5870ab40f22996aa70c0d5b6b708b23cbca37660
  • alt-openssl11-dev_1.1.1w-3.7_arm64.deb
    sha:e28eb2aa19b0832647a6125fca2dff07d76a4a34
  • alt-openssl11-doc_1.1.1w-3.7_all.deb
    sha:1cc1ec75d7ba14bf5ac8c3dc71f49cde1777528d
  • alt-openssl11-libs_1.1.1w-3.7_arm64.deb
    sha:fc110c655267ecc7b855e0e6a4f1dc4b5c2556d3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.