[CLSA-2026:1785335298] openssl: Fix of 5 CVEs
Type:
security
Severity:
Important
Release date:
2026-07-29 14:28:30 UTC
Description:
- CVE-2026-34180: fix heap buffer over-read in ASN.1 content parsing caused by truncating a long content length to int - CVE-2026-7383: fix heap buffer overflow in ASN1_mbstring_ncopy() caused by signed integer overflow when computing the output length - CVE-2026-42766: fix NULL pointer dereference when keyDerivationAlgorithm is absent in CMS PasswordRecipientInfo - CVE-2026-9076: fix out-of-bounds read in kek_unwrap_key() check-byte validation for KEK ciphers with a block size below 4 octets - CVE-2026-42768: enforce implicit rejection for CMS and PKCS#7 RSA PKCS#1 v1.5 decryption
Updated packages:
  • openssl-1.1.1k-12.el8.tuxcare.els10.x86_64.rpm
    sha:f23208825c551e8587b9fc2e8b7773da0adac5d27612efc5089a4644edf65a25
  • openssl-devel-1.1.1k-12.el8.tuxcare.els10.i686.rpm
    sha:b8da7a47b4daa126dd76b5d3614e8ac505e167346dc253d1f9a16dc37a682cdb
  • openssl-devel-1.1.1k-12.el8.tuxcare.els10.x86_64.rpm
    sha:9df7937fa85dd460bca4dbb5dd6a33373e1190ba5d2098847f9e776f05330538
  • openssl-libs-1.1.1k-12.el8.tuxcare.els10.i686.rpm
    sha:79b8c011e52736416f22f9989dc81440da37ac3c347c0af449ef96cea2dcc5b1
  • openssl-libs-1.1.1k-12.el8.tuxcare.els10.x86_64.rpm
    sha:b17d5a49e23922a32923145bebe6d2787fc18287e8d24f5e1ef3603da0db7f1b
  • openssl-perl-1.1.1k-12.el8.tuxcare.els10.x86_64.rpm
    sha:a38a592b63fdfb559a9952a0d3dc7eba97d442de6507dfdd94243a6df4de3aaa
  • openssl-static-1.1.1k-12.el8.tuxcare.els10.x86_64.rpm
    sha:bbba9a59c2b4cb5b6fa6ddcd915075eefd0ec2f0d35b843ec6f83f0d8f2b53d2
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.