Release date:
2026-09-17 12:10:23 UTC
Description:
- CVE-2026-54874: dtls: buffer only a record's own on-wire bytes in
dtls1_buffer_record() instead of taking over the whole read buffer, and lower
the next-epoch record queue cap from 100 to 16, so a peer sending tiny
next-epoch records can no longer pin ~1.7MB of heap per connection
Updated packages:
-
alt-openssl11-1.1.1w-3.8.el10.x86_64.rpm
sha:2e6ce7386e69cc483a215d8b17d2d36aa530b6d1878d60467e4ba1251d77dd9f
-
alt-openssl11-devel-1.1.1w-3.8.el10.x86_64.rpm
sha:76277cf8470a549404d0f94e3603980fa252813b57354b001dbc4a874c83e7a3
-
alt-openssl11-libs-1.1.1w-3.8.el10.x86_64.rpm
sha:b03f6c01c97fd13e17454af62eba11f74982294f959b4de5d0f5e2ab53fe89e1
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.