[CLSA-2026:1789601906] openssl: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-17 00:31:44 UTC
Description:
- CVE-2026-54874: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch, capping per-connection memory amplification
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:976c739462112182b35f5b081190b95738d0c96c05925f7c8223b651d0acf53d
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:897c38b9ba119d22484d5e6091061ac751d7a2307b525c3fdff376a91f74d774
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:3151fda94b0d677e406a35cfbf64748f0751c150cfb4bad276c3377a6c0bba4f
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:004aff5abbf186cecf76d7414f7120c2b537dc7abdf633a43983b495dbb18904
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:b7378152114ccc0ba47287140b62f97335c2b3d92a86bec7a588a9771f44d52c
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:1691e275a2a125bd74cfacaf8218802e05224998c7bd26e614748e2cd0c15aca
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:6f3a35c43bf549f3d31e713f3f13ef6c95174fdb3921ea3833cf63c08c7831ee
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:ee5c2d07d5176568aeb0997df789b494e58c9c32b012d4778c1fde0bf671439d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.