[CLSA-2026:1789474778] openssl: Fix of CVE-2026-31789
Type:
security
Severity:
Critical
Release date:
2026-09-16 22:09:09 UTC
Description:
- CVE-2026-31789: bound the length passed to hex_to_string() so the hex buffer size computation cannot overflow when printing Subject Key Identifier or Authority Key Identifier extensions
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:3166682abdb06904ddc8913b5cdbaa8d7f32fc4ebb55e196da665c2fa7d53880
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:f25cc56eb1429a11042e262c6a6de07f47b7641b792fb4298de7af10a5b772b8
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:c847d2ab8787bf9c4e39236a291361a12350ff78b12b768a1f986984acdefc33
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:16ccffd5472e9564703d056f70ad08f826988d82613de73555d3b284070a52a2
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:be1e7e95b427057a4e5fbf793b9f771f0e080cdfa998e6fdcf906a0153421666
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:28be7a0109e1f610a3637d0f10da4b63409f333c00bb3a692d6bd9bf6cf5c144
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:70e7bef106c8e14e1395635c8ab7438da4e2b1206e4acb7efd3f5a6156dba6d1
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:0f7f2eb67a5c7c34846c568db0e9d311cbcc8af9ffc881c9b35b531c688d95af
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.