[CLSA-2026:1789631727] openssl: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-17 07:55:39 UTC
Description:
- CVE-2026-54874: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch, capping per-connection memory amplification
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:ff4e887acba28f2da3ee8a50e9405f6a1d96e8b1dcbabd4c64e7d3a3da59558d
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:2b88917c7138bae1259ae2bffba68dfc2f6db6d0bedd297261937baab6837b46
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:d3d739b33d4c0682abe3c8ded9df9a72708d363ccadcf3deaeb75ea688ea29ad
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:20b1ace8cecbd5f27f80c227d2d89becf44e5ab75d8cb01bfc09df137f3e7945
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:4a2185137f15150652dd342bb95fd9b72b922d2b539e778a41cfde05f4044065
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:8a22074de656e07d3fec6417ea482ca128950ea62576acf7e5cf95bfeb16bae9
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:0fe648fde5275c31468a4c31898645bff84ade2ab6c477372d83da59b2cbf23a
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:3bc09b1f4ab296e21a2ac423205ca535b1b139dabce916005039da94da83bcd0
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.