[CLSA-2026:1777297012] openssl: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-27 13:36:57 UTC
Description:
- CVE-2026-28388: fix NULL dereference in check_delta_base() when a Delta CRL lacks the CRL Number extension - CVE-2026-28389: fix NULL dereference in dh/ecdh_cms_set_shared_info() when KeyEncryptionAlgorithmIdentifier has no parameters field - CVE-2026-28390: fix NULL dereference in rsa_cms_decrypt() when the pSourceFunc X509_ALGOR has no parameters field
Updated packages:
  • openssl-1.1.1g-15.el8.4.tuxcare.els18.x86_64.rpm
    sha:e8e644f1a6f001d9a60fa05c5e9b2f9f448fde0684c9ecafff4f7fb32a372ea6
  • openssl-devel-1.1.1g-15.el8.4.tuxcare.els18.i686.rpm
    sha:0b26d56045a4b4f8428c7695969f843502d7057bc433afb3183e06671caefc81
  • openssl-devel-1.1.1g-15.el8.4.tuxcare.els18.x86_64.rpm
    sha:7cca736d6b4bddddff4edd1573838a0437e3c3c2ed886a19a08f8028461c816c
  • openssl-libs-1.1.1g-15.el8.4.tuxcare.els18.i686.rpm
    sha:5af3e87a8deb35d0f76f24599ba9c734ac690891ab4b6c8f7203fb81bf41c30b
  • openssl-libs-1.1.1g-15.el8.4.tuxcare.els18.x86_64.rpm
    sha:ce598f7924f03c4edc352be3ae229110b28bba12f0fa9f332fb909629a9eff1e
  • openssl-perl-1.1.1g-15.el8.4.tuxcare.els18.x86_64.rpm
    sha:6ab031b636e1a845239aa9167ade9d5e7f546037ea811cccecdbddf7751d62fb
  • openssl-static-1.1.1g-15.el8.4.tuxcare.els18.x86_64.rpm
    sha:1dd6250795c810d2138796b940ac312089b152fda39983b2debe49968b14aebf
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.