[CLSA-2026:1777724562] openssl: Fix of CVE-2026-28389
Type:
security
Severity:
Important
Release date:
2026-05-06 07:02:14 UTC
Description:
- CVE-2026-28389: fix NULL pointer dereference in dh_cms_set_shared_info and ecdh_cms_set_shared_info when the CMS KeyEncryptionAlgorithmIdentifier parameter field is omitted
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:630908cffd90ceb9490e5ed39d7470ca5a7ba76ff8e3f784dc94090aae03d8ea
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:bdd98ac0e42ce39261c8c24f1e1c481cbf16c12320a38119992a408cc1dc5882
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:9cec5ef0c82543ee3d2245946d87577cfb84cf3099c6914c823a98a8b71f5f57
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:b1d7f5103775499e868cd2374bb726db50821fb2207b358449a0997472ae4ffa
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:5411e49ddec342f81b0c44bda56678f00a76b8852041a8e36dffad5c58283cfe
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:60a405c59d5e224f11a559317356ae704a13a6c996ae93d33d3e8273b22f8ed1
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:25c83a4a96bd57568cfc05a6b846fa8f631fd2cca4a81fa33b93158ecca92986
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:6c0b098c91ddfc1b2b8eabdb0590038a4271f9fe5801278bfe9a1c3be70fff49
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.