[CLSA-2026:1789604584] openssl11: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-19 00:48:42 UTC
Description:
- CVE-2026-54874: copy only a DTLS record's own on-wire bytes when buffering it for a future epoch, instead of taking ownership of the whole ~16KB read buffer and allocating a fresh one
CVEs fixed:
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:69ddc4583eadace5f87f990bee1713379c5461e145070a21b3cff1a363f73e5e
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:02e8e52924b456775f5808de9e0336feef1db04e66de2c0da463278ae0ea6b72
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:6a18c5f126c80d200b592e79ba7bd5890722ce079e20e65e3b3513ff4a7f7cec
  • openssl11-static-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:fff2dda781cd882b2bfab7c9033aee116be97e0e298a015114ff41cd5e1f9651
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.