[CLSA-2026:1786005845] openssl11: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-08-06 08:44:15 UTC
Description:
- CVE-2026-45447: fix use-after-free of a caller-owned BIO in PKCS7_verify() when the SignedData digestAlgorithms field is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:4051f832abcb67c8b0d6ac5521c97a576b2e8fa3a65c2b44ec1f0a53174d994a
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:eb1264b379849429000caa72a900b504ca256e38aa955c68b1bb2207ea480f4a
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:7b31a8bf24893ba40f6e08e9763592b7fa212b25e97e25b316ab52bf21523fb0
  • openssl11-static-1.1.1k-7.el7.tuxcare.els3.x86_64.rpm
    sha:dc1d53145eb3f1010dbb350e77329327d6ffcf73dc1c2d63a421c3fba28e00e9
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.