[CLSA-2026:1781548297] openssl: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-06-15 18:35:15 UTC
Description:
- CVE-2026-45447: fix use-after-free in PKCS7_verify() when SignedData digestAlgorithms is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-24.amzn2.0.20.tuxcare.els1.x86_64.rpm
    sha:529b0ac105607ec274a750367c35d207e1ac2e1e7e17acc7025a84f0e872c32d
  • openssl-devel-1.0.2k-24.amzn2.0.20.tuxcare.els1.x86_64.rpm
    sha:9fa4d683095a450882ffdb80af2049998a60c85b26f6299af6cc0116b94a843a
  • openssl-libs-1.0.2k-24.amzn2.0.20.tuxcare.els1.i686.rpm
    sha:af5b306e105a66072c1690ed544bf51d171ca8a4eabaeb5365bddbcb1e5ae4a7
  • openssl-libs-1.0.2k-24.amzn2.0.20.tuxcare.els1.x86_64.rpm
    sha:7593f689d97382ec5e6c2f85753fbb68e240eb0ac704e4a66ed94c30579fc339
  • openssl-perl-1.0.2k-24.amzn2.0.20.tuxcare.els1.x86_64.rpm
    sha:efd4e6340fc78486013cff2dd94f34f1238cefbe91899869558661d7d0cafe1a
  • openssl-static-1.0.2k-24.amzn2.0.20.tuxcare.els1.x86_64.rpm
    sha:299da1aa7267ac7d063f225353f4dac22ac6c9cec407b555a17eacdeef1c6197
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.