[CLSA-2026:1789646479] alt-openssl11: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-17 12:01:29 UTC
Description:
- CVE-2026-54874: dtls: buffer only a record's own on-wire bytes in dtls1_buffer_record() instead of taking over the whole read buffer, and lower the next-epoch record queue cap from 100 to 16, so a peer sending tiny next-epoch records can no longer pin ~1.7MB of heap per connection
CVEs fixed:
Updated packages:
  • alt-openssl11-1.1.1w-3.8.el8.x86_64.rpm
    sha:2126ab69b44c8f7d9fcd7b03a75cc8c7152af370571e41384148be255134d837
  • alt-openssl11-devel-1.1.1w-3.8.el8.x86_64.rpm
    sha:6a0379b4b8b453f4c9fcda2f945264370456bad2d66624d13767f90c08e01cf0
  • alt-openssl11-libs-1.1.1w-3.8.el8.x86_64.rpm
    sha:45ca9cf7b995cdaee1bb8afc0334d232613fffe7ec6cef7a01e4605a560370c7
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.