[CLSA-2026:1787059408] openssl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-18 13:23:45 UTC
Description:
- CVE-2026-34180: widen asn1_ex_c2i length to long and reject truncating lengths to avoid an ASN1_STRING heap buffer over-read - CVE-2026-42766: guard against a missing CMS PasswordRecipientInfo KeyDerivationAlgorithm to prevent a NULL pointer dereference
Updated packages:
  • openssl-3.0.7-20.el9_2.tuxcare.1.els21.x86_64.rpm
    sha:c3ba867d998f2134e5838030c42c3e8091fad9ea72b0be86a5f2770aee477dfd
  • openssl-devel-3.0.7-20.el9_2.tuxcare.1.els21.i686.rpm
    sha:9ef1f0ad20190187e2e9ec1f4e7256a48fd7dce76888e9e2abf5b52281c09c60
  • openssl-devel-3.0.7-20.el9_2.tuxcare.1.els21.x86_64.rpm
    sha:b05b9fb36d8111099d6cc786cc747f1c2b6c35b118c146623d22152349344c87
  • openssl-libs-3.0.7-20.el9_2.tuxcare.1.els21.i686.rpm
    sha:f1767c494a5b591c33b931dfe583f610105ec3dee649ab19af424c470228cfd7
  • openssl-libs-3.0.7-20.el9_2.tuxcare.1.els21.x86_64.rpm
    sha:5540490d52e17a59d15efb27cf76412f49151626c6b2fa4c831a0ef5e7efd9fb
  • openssl-perl-3.0.7-20.el9_2.tuxcare.1.els21.x86_64.rpm
    sha:e40c47120d17b2210155438eb90c63ca7320183380051a4188037e59e048e106
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.