[CLSA-2026:1789605435] openssl11: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-17 00:37:27 UTC
Description:
- CVE-2026-54874: copy only a DTLS record's own on-wire bytes when buffering it for a future epoch, instead of taking ownership of the whole ~16KB read buffer and allocating a fresh one
CVEs fixed:
Updated packages:
  • openssl11-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:6d31c2c473953dd671424cd0b7fd9d19be1b42128ee67ef9f8179ffe0a7d7ffa
  • openssl11-devel-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:abe7b142d254f1d3ac8055a844d56ad194bb3408eee69ec4b8539652fb14625c
  • openssl11-libs-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:528b93240e11029813be3715cd3ff77dc9bfb8f7b0f46a3f3dae604d4c8ad55b
  • openssl11-static-1.1.1k-7.el7.tuxcare.els5.x86_64.rpm
    sha:5a7cca37be3fc8768b6e1b4fa8040f76a00d07bd14200cafcc54e7899f7849df
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.