[CLSA-2026:1791192749] openssl11: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-05 11:29:34 UTC
Description:
- CVE-2026-84782: reset init_off before a DTLS retransmission and skip it while a handshake write is suspended, avoiding a heap over-read - CVE-2026-35189: build relative CRL distribution point names only during CRL matching, avoiding unbounded heap growth when caching extensions
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els6.i686.rpm
    sha:1ba268eee8549a69e9e91f724b599cfcac8da441edcdf09d259497f517b53784
  • openssl11-1.1.1k-7.el7.tuxcare.els6.x86_64.rpm
    sha:860951062f5eede3c05fef3e199a7a1367d1bdb0a449ed4495f94176080902da
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els6.i686.rpm
    sha:426640813c554231123f34c079d701eced07288ce068cad013a002c3a901dc5e
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els6.x86_64.rpm
    sha:f7dfa5aaf462bf61831170971ecf2d02192925caf82752be76987381985b6b73
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els6.i686.rpm
    sha:252cf9985496654e6846c0a435458243773b4308fb5f35d4ebcadb1640b0e267
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els6.x86_64.rpm
    sha:3422624d2fd2ca25416573538adf9b470913d4096f7b25ce5ea6014b279eab00
  • openssl11-static-1.1.1k-7.el7.tuxcare.els6.i686.rpm
    sha:b153147c71e3bb2aa727893c6ccba7057d1b741047d37f72cb0eb559cb229983
  • openssl11-static-1.1.1k-7.el7.tuxcare.els6.x86_64.rpm
    sha:92256d5106c65fc783342ee029c74e9bfe174349bbc794a0e1e23e336d82e934
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.