[CLSA-2026:1781209013] openssl: Fix of CVE-2026-45447
Type:
security
Severity:
Critical
Release date:
2026-06-11 20:17:09 UTC
Description:
- CVE-2026-45447: fix use-after-free in PKCS7_verify() when SignedData digestAlgorithms is an empty ASN.1 SET
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:ae4a0822ad688f88181991ae5f725f5aea359be5d66d812f54f6c23e2389972e
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:d0b15ef13301f3f9ed51eec1ea035e920e2b7357c587af9ca1f6f824f9949cfa
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:cef24765a0530de7085e9da7b5f94f4e7636183ab3ec54e205eae142efd61b19
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:56d26b3d81bbdab6d559e1de3b031b8ac3653c5573755830b4e48c1e75f5bfa0
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:8c4fa6fda8e8b84aa632e05fbb0ea87aa9fc9de94736117dedf92804f327aa2e
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:9e5c7291acda98ebaf6b53d6295adef5e911735c347a3f72035b83b150bd5209
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.i686.rpm
    sha:aa09c0a572019eaa58589d10ce9f6f26857349098babfcd182544dca14ef6805
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els11.x86_64.rpm
    sha:a9f152006f562f598577b266204a8fcd884aba5ba53b53f6e60a7ffd240f0c92
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.