[CLSA-2026:1781253686] Fix CVE(s): CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-06-12 08:41:43 UTC
Description:
* SECURITY UPDATE: fix use-after-free of caller-owned BIO in PKCS7_verify() (pk7_smime.c) - debian/patches/CVE-2026-45447.patch: fix use-after-free of caller-owned BIO in PKCS7_verify() (pk7_smime.c) - CVE-2026-45447
CVEs fixed:
Updated packages:
  • libssl-dev_1.1.1n-0+deb10u6+tuxcare.els4_amd64.deb
    sha:0c97b55c6bd800eedd8d7daadeec02e5762add9e
  • libssl-doc_1.1.1n-0+deb10u6+tuxcare.els4_all.deb
    sha:a3020a3ffc372178f89a4720d1a046b62c5a13ce
  • libssl1.1_1.1.1n-0+deb10u6+tuxcare.els4_amd64.deb
    sha:22e994d1a9c8c969ae1afaf9c000d046246bd2c2
  • openssl_1.1.1n-0+deb10u6+tuxcare.els4_amd64.deb
    sha:79c5dbdc4b36147a630b34d48f4f9e96e042df28
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.