[CLSA-2026:1785922190] alt-openssl11: Fix of CVE-2025-69419
Type:
security
Severity:
Important
Release date:
2026-08-05 09:30:02 UTC
Description:
- HollowByte: grow the handshake init_buf incrementally as data is received instead of pre-allocating the full peer-declared message size, so a peer that claims a large message but never sends it can no longer strand memory (ELS-2635). Backport of OpenSSL 3.0 commit c5785a5e35 (PR #30794); handled by OpenSSL as a "bug or hardening" fix with no CVE assigned
CVEs fixed:
Updated packages:
  • alt-openssl11-1.1.1w-3.5.el9.x86_64.rpm
    sha:e0afeb803065b97497ad28f06fada53a652d16a1a8c48e6d6b5a35821e568e1e
  • alt-openssl11-devel-1.1.1w-3.5.el9.x86_64.rpm
    sha:fe52514a2fbc26a65715536b1d344a91d433bc2712137529057f046d25d63143
  • alt-openssl11-libs-1.1.1w-3.5.el9.x86_64.rpm
    sha:fcd6db47069c49dc6fed8978fa5a3dd0dcde86b4216532a89755c381d5ed779f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.