[CLSA-2026:1786544493] openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-12 14:21:45 UTC
Description:
- CVE-2026-34180: avoid truncating a long ASN.1 content length to int in asn1_ex_c2i(), which caused a heap buffer over-read for primitive elements larger than 2GB - CVE-2026-42766: reject a CMS PasswordRecipientInfo whose keyDerivationAlgorithm is absent instead of dereferencing NULL
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:b5198ea626de324213f09994f625a13271c169c2b502b9e5dc6a50af2b5a41ae
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:6de92c94d1b53309cd687710fe641c663d98fefbb76bd5abba0f9ab2b3516032
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:2aa80e1708d8002e613d23dbe81560e5b139298bb3dee27417ec8ace710ad8da
  • openssl11-static-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:da850b5a02162fb2011b0730c9134566621d04df832befb8e3116a09feec5aa1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.