[CLSA-2026:1791199702] openssl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-10-05 11:28:35 UTC
Description:
- CVE-2026-84782: reset s->init_off to 0 in dtls1_retransmit_message() so a DTLS retransmission is read from the start of the queued message instead of the offset left by a write suspended on WANT_WRITE, and skip retransmission in dtls1_handle_timeout() while such a write is still parked - CVE-2026-35189: defer building the full name of a nameRelativeToCRLIssuer CRL distribution point out of setup_dp() and into crl_crldp_check(), so a certificate with many relative distribution points no longer caches one copy of the issuer name per entry
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els5.i686.rpm
    sha:b0093396e90e833ea82791c3de5285124169c562f8b298f9d13ef45c28900b0c
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els5.x86_64.rpm
    sha:bb7f8713078306e424543662c1d7b7e92499b47058bedcee1bd305dc80a030dc
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els5.i686.rpm
    sha:e1246d3b4e98cf3fc17cb1ffbcc6ddc12bdff4f2cb0bfb767038f9201878fb8a
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els5.x86_64.rpm
    sha:70bd13b7da46b7b976b6de7bcbdf3c666211b6e0d3f839f0671c12496e8e7c3f
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els5.i686.rpm
    sha:88dd26bfed1021306ca29e8e72e0da93f331e764a3cf3e189ee0925152663d54
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els5.x86_64.rpm
    sha:9cac1f07a2501aa1718f9cc6cdb4a66e959c9135f9feacc626a11feb76bc54b4
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els5.i686.rpm
    sha:f75f8d57279a8adc61a2bc7d1f38e9eb62c4d085d35bf046c45e592577c79d4c
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els5.x86_64.rpm
    sha:6850b8b118e8d7324bf4b37e220334279afd7e7c8491e998b974ceb7a8920d1b
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els5.i686.rpm
    sha:b5d49f30f87a8f3e26b23e19cca8c53b76a6d1d8f8e674d6d43608aa8d69e708
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els5.x86_64.rpm
    sha:aa58edd32f415c2702660d7b7991657e5c3749fa68c26790eae9fb06ca42f67a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.