[CLSA-2026:1777547052] openssl: Fix of CVE-2026-28389
Type:
security
Severity:
Important
Release date:
2026-05-02 01:07:38 UTC
Description:
- CVE-2026-28389: fix NULL pointer dereference in dh_cms_set_shared_info and ecdh_cms_set_shared_info when the CMS KeyEncryptionAlgorithmIdentifier parameter field is omitted
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:d6c9bdc33d1a271e17287858a5fee48b08aefa09db74fd2e1fb216f52d9ab803
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:bfdb2ec2e639c58231af4a88fab081a5246538a5fd24b37b80ca088229954304
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:129c3ec22b6392f92967abef7e9fc0748cb1677090cf08e8717e34999a815f4b
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:ba344b528e08a946ab41a65aab8fb91235c144d8f9c6ed8b942954ca48639e5c
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:a483b0f1bb62a8499a28429b0a6baebdf7ec9f36f8b5a7ce590f592b1731ec55
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:e7637710d670cb14ec9cddd12c361093e66afc8a761368e606802fa5df543d3c
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:0ecbcb32fb9ba3f666e61a4d9751202b9fd6d9f823aea4eb8cfc6b45f8814a8d
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:6bb5f6e2c2afb355a8f6db8a354cf746aa79a73d434f568bcf22e2534a377762
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.