[CLSA-2026:1787229627] Fix CVE(s): CVE-2026-34180, CVE-2026-42766
Type:
security
Severity:
Important
Release date:
2026-08-20 12:40:39 UTC
Description:
* SECURITY UPDATE: fix ASN.1 decoder length truncation causing heap buffer over-read (tasn_dec.c) - debian/patches/CVE-2026-34180.patch: fix ASN.1 decoder length truncation causing heap buffer over-read (tasn_dec.c) - CVE-2026-34180 * SECURITY UPDATE: NULL check pwri->keyDerivationAlgorithm in cms_RecipientInfo_pwri_crypt() (cms_pwri.c) - debian/patches/CVE-2026-42766.patch: NULL check pwri->keyDerivationAlgorithm in cms_RecipientInfo_pwri_crypt() (cms_pwri.c) - CVE-2026-42766
Updated packages:
  • libssl-dev_1.1.1n-0+deb10u6+tuxcare.els5_amd64.deb
    sha:6fbbbcc01bc9f14d1349abed4ef4181758fc647d
  • libssl-doc_1.1.1n-0+deb10u6+tuxcare.els5_all.deb
    sha:fbba17b12f417620e08717b0cbe2927f372adb39
  • libssl1.1_1.1.1n-0+deb10u6+tuxcare.els5_amd64.deb
    sha:41924f621e7a630c7c348862e75d54bb0436b124
  • openssl_1.1.1n-0+deb10u6+tuxcare.els5_amd64.deb
    sha:80a18c4226477f16aba2fcc10279e89d5fd89917
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.