Release date:
2026-09-17 11:46:09 UTC
Description:
- CVE-2026-54874: dtls: buffer only a record's own on-wire bytes in
dtls1_buffer_record() instead of taking over the whole read buffer, and lower
the next-epoch record queue cap from 100 to 16, so a peer sending tiny
next-epoch records can no longer pin ~1.7MB of heap per connection
Updated packages:
-
alt-openssl11-1.1.1w-3.8.el9.x86_64.rpm
sha:6eedcc8db86c78eb230afb3b14b8f579c39803b7db2c65ab6068d7d503a6c126
-
alt-openssl11-devel-1.1.1w-3.8.el9.x86_64.rpm
sha:8e967379633a372572f319406bee5b40347dd365829fe990540e8b0827193e8d
-
alt-openssl11-libs-1.1.1w-3.8.el9.x86_64.rpm
sha:b6975e25a3338db51e9c8113f9d88ee8dc901664b13db2cbd582bf281fd40ff2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.