[CLSA-2026:1786473548] alt-openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-11 18:39:22 UTC
Description:
- CVE-2026-34180: asn1: avoid content length truncation in asn1_ex_c2i() so a primitive element longer than 2GB can no longer cause a heap buffer over-read - CVE-2026-42766: cms: check that PasswordRecipientInfo.keyDerivationAlgorithm is present before dereferencing it, avoiding a NULL pointer dereference
Updated packages:
  • alt-openssl11-1.1.1w-3.6.el8.x86_64.rpm
    sha:b6e2d5a61776d665ab929fa7259d2d17a2f5177fc5b95710a4a22e111532c01c
  • alt-openssl11-devel-1.1.1w-3.6.el8.x86_64.rpm
    sha:4c47f6313902980c2a6a7ae3d07438c9092179232b676af9bf372a96298af4dc
  • alt-openssl11-libs-1.1.1w-3.6.el8.x86_64.rpm
    sha:a26bd65c63bfe74df79ed49bdb39042d58e3fc8113c3eca01292b65842711ebb
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.