[CLSA-2026:1781208804] openssl: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-06-11 20:13:40 UTC
Description:
- CVE-2026-45447: fix use-after-free in PKCS7_verify() when SignedData digestAlgorithms is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:b37da02b810e687accfee9ac057bcb9376db1a61f2fc847803b3f1ab66152017
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:614afec594d4e614ddbe2640a95f010144948b0a35b2df95caeb066c9c431030
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:12d1d410a9ad5acbb305d8f8b1204efe073453467ffc7fb5c38170839c854911
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:73fba551b2641dc7b5c96ad27388acd2f07ba14b49a69317a90536352953987b
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:a8e1cefc31e1ce142bf124a7a40b548b3c15b7e164449b0156e67c085f003786
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:12c7a449843625cd2ddf48dc465bc300163afeded675a731b3ee39ff60d51b16
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:e8416e92461d9bcca5c1c73ecd3fb4f75f0020bcaa531a827daa2b7fc648f4cb
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:c9921fd97b234134affb739df502a473fd04b61f5820deb3ed98b730b66337ae
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.