Release date:
2026-08-11 18:39:22 UTC
Description:
- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a
primitive element longer than 2GB can no longer cause a heap buffer over-read
- CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm
is present before dereferencing it, avoiding a NULL pointer dereference
Updated packages:
-
alt-openssl11-1.1.1w-3.6.el8.x86_64.rpm
sha:b6e2d5a61776d665ab929fa7259d2d17a2f5177fc5b95710a4a22e111532c01c
-
alt-openssl11-devel-1.1.1w-3.6.el8.x86_64.rpm
sha:4c47f6313902980c2a6a7ae3d07438c9092179232b676af9bf372a96298af4dc
-
alt-openssl11-libs-1.1.1w-3.6.el8.x86_64.rpm
sha:a26bd65c63bfe74df79ed49bdb39042d58e3fc8113c3eca01292b65842711ebb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.