[CLSA-2026:1777553052] openssl: Fix of CVE-2026-28389
Type:
security
Severity:
Important
Release date:
2026-04-30 12:44:17 UTC
Description:
- CVE-2026-28389: fix NULL pointer dereference in dh_cms_set_shared_info and ecdh_cms_set_shared_info when the CMS KeyEncryptionAlgorithmIdentifier parameter field is omitted
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:7100195034cc9e578f5d9890cf4d2bb3a70814386a5b9d3a01c82bc9feebd25c
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:f486f0d8f89cb2c892fb541bee8251a1eb27d63c8e52e813d14c40bfadbfe9d4
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:e770e66393e5c235523c86c886eb26416e0ba36905c89bdd7c0ceeb848abe295
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:dcdcf2bde01987fe455c797bf9d9a357b133fd83699d9bbb99c212a883ae16a6
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:0f4f7536796bb9b434ad2ca7d6530196902a9313808c7fb6bf23de86363adf57
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:c45a4011f21f468c23d62542a4e6f2513a5bb1579069ee1c1ebb498b465021a7
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.i686.rpm
    sha:1828bb7897539f23b9ecb739bd735a083fd8d37166de7f8001df3a215b9e12a6
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els8.x86_64.rpm
    sha:77fb0e1202fd9966797f3f2f79bcd1c5c073c48efe4932eb04fe5aaac04137a2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.