[CLSA-2026:1780513164] openssl: Fix of CVE-2024-2511
Type:
security
Severity:
Low
Release date:
2026-06-03 18:59:38 UTC
Description:
- CVE-2024-2511: unbounded TLSv1.3 session-cache growth via not_resumable session duplication; cache full handshakes only and clear not_resumable on dup so the entry remains evictable
CVEs fixed:
Updated packages:
  • openssl-3.0.7-20.el9_2.tuxcare.1.els12.x86_64.rpm
    sha:d605979784d4a0ab2cedb5a419789e628d6c8a21b18bf2266b258640609c02de
  • openssl-devel-3.0.7-20.el9_2.tuxcare.1.els12.i686.rpm
    sha:b3f5e4ffe4f4cb0e751432c02e26e485ff2efb1c7f19c5c717e37ac563f78a39
  • openssl-devel-3.0.7-20.el9_2.tuxcare.1.els12.x86_64.rpm
    sha:36b34d512a158616d1a4929c082bc580ba07f174c5aa1971845bad6ffe6c6ba2
  • openssl-libs-3.0.7-20.el9_2.tuxcare.1.els12.i686.rpm
    sha:27d29f46bda8996b5119d4c16651fb6d1edc633d5ad473a2d74a07a6a08dba0e
  • openssl-libs-3.0.7-20.el9_2.tuxcare.1.els12.x86_64.rpm
    sha:f75897cd3334bbc68fe2e96158007548d940fdeed9408fd3e108071632382eaf
  • openssl-perl-3.0.7-20.el9_2.tuxcare.1.els12.x86_64.rpm
    sha:9224f9ec81c36cee1586d3d3412d3e1d25609633f15a8a61097cbdde23dbf29a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.