[CLSA-2026:1789474528] openssl: Fix of CVE-2026-31789
Type:
security
Severity:
Critical
Release date:
2026-09-15 12:15:39 UTC
Description:
- CVE-2026-31789: bound the length passed to hex_to_string() so the hex buffer size computation cannot overflow when printing Subject Key Identifier or Authority Key Identifier extensions
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:42f9197e9bff6861d2955beca1914177a266fb78122382fa8727d994ba40a014
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:17e0996bec6dcf1f2594e7e15ef90a7316ed253c79e9bfd9161522fed5e673a9
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:446b8a4abda899ccc032fda4523aed491779788cefbdf4d2bb2e38a880c526a9
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:5761069e1c9d6ddc5c427cc5391324638d76b0765421c41559c2403a488153e2
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:c2c653f1b04d19ecae3875ce576c9fb06541fa95466be2d56a03277f8db94b85
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:262f5f0b0b3159ab3ca45343985f292add25754995d4c517e797c45eb7fb2259
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:cb3ec592e014186111b1c766df6991da655793013c04be16a5f815529aa829e6
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:1d70c908016b6c4cef85729c99af564778f930f9d69b25c384a51c29302ac068
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.