[CLSA-2026:1777552800] openssl: Fix of CVE-2026-28389
Type:
security
Severity:
Important
Release date:
2026-04-30 12:40:05 UTC
Description:
- CVE-2026-28389: fix NULL pointer dereference in dh_cms_set_shared_info and ecdh_cms_set_shared_info when the CMS KeyEncryptionAlgorithmIdentifier parameter field is omitted
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:6aaf285c257b01e43da7ad82ec97b0aae1c7a522dcfad510b1f2409d98b89c6b
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:ffae0e078f3b69c05dfb3e4bc146fc55ee653af64809f6225a87e2e7477ad090
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:264f3239be3361cbbdb1e6f12110bc6f63118868534bb5a78e49179db349932e
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:9889e885a1232741dc0578949bdb43807a9d9984cee1cb9b28f6b482203357c9
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:3929d9a3ad4ba0154236e04d60608743e59ed636580aa4c41edf4340f6c46c11
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:5b88dad3d1ea97770df1ddc720aab7a2ee06d243d715241163c1d3e2c7d4fe89
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:29558782ff6b45ae16909d4a87806d32ac9f348e4e23e163366ba919be6573db
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:be3c4b94d83046ae767df797d792e780bc358dc76ec6054b35119c5c0b8fc37a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.