[CLSA-2026:1777567430] openssl: Fix of CVE-2026-28390
Type:
security
Severity:
Important
Release date:
2026-04-30 16:43:54 UTC
Description:
- CVE-2026-28390: fix NULL pointer dereference in rsa_cms_decrypt() when CMS RSA-OAEP pSourceFunc is missing its parameter
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:7378230468c7218e84b57e4cd06f7d7c8d985359563967263da38bc6b7ed335e
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els9.i686.rpm
    sha:11dc6789b890f50f017b5240a136e86d112c3e4f3baedb49c41069305badd117
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:d984eaae50d58cb3aefcf89331033ed1d0d668d6ef4529c0889459668459853a
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els9.i686.rpm
    sha:303ac859f3bc1ea35018b2ab8157be8c502ae6ee2143f5fffd97444ca042bfa9
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:05c1c9df75388b57c5ecc38fcb0c9d59a3df8c69e0f7aa7a059df8870d70067a
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:1a6844dc5e048584a5aa200cbde1ac36a14dadd95da3cc36c99553a553254fb7
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els9.i686.rpm
    sha:f6c19a390ff2eb510db116edb71fbc62c0ec5b9f6cf343d22bcb271096fb78cd
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els9.x86_64.rpm
    sha:f55fa178853874833a8c22526b3adf433f65e669edc09df3c0a5fe18aa0d96a3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.