[CLSA-2026:1789475205] openssl: Fix of CVE-2026-31789
Type:
security
Severity:
Critical
Release date:
2026-09-16 23:31:44 UTC
Description:
- CVE-2026-31789: bound the length passed to hex_to_string() so the hex buffer size computation cannot overflow when printing Subject Key Identifier or Authority Key Identifier extensions
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:f4a63093e345e5a8ebde5b0093eee493ae6127b96a5631b748912900be77d896
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:97a999dfe8ef96a8fa043c67e6a659135064f8a1add7a21aca5c2b6df738151c
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:e97ae6fb3bef137ddc7dae65a08a73a9e90fe8ca0c6f10c37404237905aa0da9
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:210a9e5a8d2cff33ad7e4e89145c3224944dfca8a6caaa453528a18477faf04a
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:7b34e83b0509c0e22fccb9b86c5310fb4d872515fa0e59dd5ddf863ed42d0930
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:7673f7ff21b47adc01963b26be090837cb81179a5d368cc538871b967714497a
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els4.i686.rpm
    sha:f42f4b9a52573c4038f7f2bb328fe93c1765ccdf0776e0f47921b2ffe9f53320
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els4.x86_64.rpm
    sha:83106dc91f855117109f289094eb9873fd526748234ae258b66920720838387e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.