[CLSA-2026:1781209312] openssl: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-06-11 20:22:08 UTC
Description:
- CVE-2026-45447: fix use-after-free in PKCS7_verify() when SignedData digestAlgorithms is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:bc1d1004f9ebddf7bdafab8360ac5999ff69aae4bec615d177fa7176b539ecec
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:a53285df77ea7095f6b619e366300b07f57480b8dda7390941e03e76d72340f6
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:3046c35b88cb83e223f486e40dc5704d9fdcc638e25c94f0b01f8ea713f0eccf
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:fd40ea0b48628b8133a3018a3b555829e035b67b2fd1110fe3e4c30438e50acd
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:dcb2669978d566b6fd3253da2a058c5e92b70c2e072ce58d80eeacedbc2ea356
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:1b669f11a2677488f36c56e9c117c26291d1b77c2afae2d96052a206f87c8efa
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:8b1035cfa63ab0cd902fc6eb50c6a2db62adedd598408d5cdc255fb6f955cd4f
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:1f5c6b54d437acde260427a835efa9c27026458df67a733015d875083fa2ac9f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.