[CLSA-2026:1781208261] openssl: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-06-11 20:04:37 UTC
Description:
- CVE-2026-45447: fix use-after-free in PKCS7_verify() when SignedData digestAlgorithms is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:3907b56321f14cf625e1b2fc326c1a9d60e0f38e539a0d882fa39b296347a4e9
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:4db832c5292d288c3cbb774674fcad832dac0569c2b73b1b6254c672ce66120a
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:e1226eab2f828d0d9db2dbbee2a9ca93ed563a962e4d7aabe05a7ed72793168b
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:ea2efb415f07faf27bd52353762a04c43f013a611380ec5f2e69eb0dc053c5b9
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:f30587082d5846cf57c2da8926f4454ebbeaf9c875c0f32530f5bc608bd2f95d
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:1722eea29a5ee18cce6d04c7c0963dac51d36802aaeae6b9858fdf012a33b6c6
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:36fc5b31e23819858fbdfe918ef3d4fc91e031d570c5909f419be16c25df8341
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:73754340d3ca30384b4b87d886b99f48874cc31e8bf2e6192ae77e352e921b1c
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.