[CLSA-2026:1789645117] alt-openssl11: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-17 11:38:47 UTC
Description:
- CVE-2026-54874: dtls: buffer only a record's own on-wire bytes in dtls1_buffer_record() instead of taking over the whole read buffer, and lower the next-epoch record queue cap from 100 to 16, so a peer sending tiny next-epoch records can no longer pin ~1.7MB of heap per connection
CVEs fixed:
Updated packages:
  • alt-openssl11-1.1.1w-3.8.el7.x86_64.rpm
    sha:a3f5c5f778cdf25a0a3b4fcab6d9783473981f389e5804bb902ae2a8d3622717
  • alt-openssl11-devel-1.1.1w-3.8.el7.x86_64.rpm
    sha:c11ba468f1a5006581a82763bd2696ddff65dc0998abeff7295f1ff0bb0bb312
  • alt-openssl11-libs-1.1.1w-3.8.el7.x86_64.rpm
    sha:be8d23152b8eddf56241e718aebac45aad24b5290130b5755835b6e9d5cb97c0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.