[CLSA-2026:1786972455] openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-18 08:35:20 UTC
Description:
- CVE-2026-34180: avoid truncating a long ASN.1 content length to int in asn1_ex_c2i(), which caused a heap buffer over-read for primitive elements larger than 2GB - CVE-2026-42766: reject a CMS PasswordRecipientInfo whose keyDerivationAlgorithm is absent instead of dereferencing NULL
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:4b30829b54c384ad53ebe4725ee1408043b6348d57f17ca9a17f68ec03eede81
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:8ba5b23331e109d89327580fd3870b87959e7861744b2cb0b315aa13c542cc32
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:e62707b0206749d64f1fa977751acfc6ddf9e360b50e5bb71445df974d7a5d7f
  • openssl11-static-1.1.1k-7.el7.tuxcare.els4.x86_64.rpm
    sha:3c61623012aafcb5bbf007af2ca6e89183147ec6550accb4f3f73519d9151231
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.