[CLSA-2026:1777566580] openssl: Fix of CVE-2026-28390
Type:
security
Severity:
Important
Release date:
2026-05-05 21:08:17 UTC
Description:
- CVE-2026-28390: fix NULL pointer dereference in rsa_cms_decrypt() when CMS RSA-OAEP pSourceFunc is missing its parameter
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:18617ee01115970b6c4b032e318a577a18f2fe531ba57a0ed589134df536d1a5
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els9.i686.rpm
    sha:2088f84c6a6f2aa3e0b4ccc3e48fe63ab6137c1aa70dbafd759eca7dc1b25789
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:fec290b25f8e95182ac2159b20f5f84600461566a84791c40f9319d5e386bc9d
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els9.i686.rpm
    sha:70fb28775168f0cba1a42f4bf9b6f1be499d6e5b7bc3aba62db21e7fdcd4ddf1
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:b1b6524e3088852985a24f687b70e3a8d13c2d9db2836f879b1e345fe7d30637
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:611f538a72df60e10f67fb732dc06daa0968073ccbd594c2f14963db7c75fee3
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els9.i686.rpm
    sha:8f40610941cf3b21e2ccac1ae29a50bdb2a659773c1faf61992437c076d295bc
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:97511a230d3b6f7100673e5cb70b86dfc95c36404f933e9b883a9932aaa55007
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.