Release date:
2026-09-01 14:13:11 UTC
Description:
- CVE-2026-54874: fix excessive memory use when buffering DTLS records for a future epoch by copying only the record's own bytes instead of the whole read buffer, and lowering the unprocessed-records queue limit to 16
- CVE-2026-63072: fix 8-byte out-of-bounds heap write in CMS key unwrapping by sizing the AES-WRAP-PAD unwrap output buffer for the worst case
Updated packages:
-
openssl-1.1.1k-12.el8.tuxcare.els11.x86_64.rpm
sha:21cfc03bbd07f18807ef8cea672918a03b2ffa8355119e4a360d315f845d42d1
-
openssl-devel-1.1.1k-12.el8.tuxcare.els11.i686.rpm
sha:280c96233a300ecb63e01f172d59f0f942e6f444eb13ac9cbbfec2de5e0b62ce
-
openssl-devel-1.1.1k-12.el8.tuxcare.els11.x86_64.rpm
sha:20549a183f0418158f1525cf028b7579543ba3d4475e97db7361db230fc49b0f
-
openssl-libs-1.1.1k-12.el8.tuxcare.els11.i686.rpm
sha:5275627f5ab98dc1561d263b37cf2a51a5291e37f7ec0f361b60bf6bd78a2c57
-
openssl-libs-1.1.1k-12.el8.tuxcare.els11.x86_64.rpm
sha:fd7ada55427c0325bd92f38da78bf55b28e355c587a17d6cf54a5aedae7d5cfe
-
openssl-perl-1.1.1k-12.el8.tuxcare.els11.x86_64.rpm
sha:6c1b7c04745a004e0349f5bbb97b3d9971e57cf8ad636e8a731e36f34b73e3d4
-
openssl-static-1.1.1k-12.el8.tuxcare.els11.x86_64.rpm
sha:d4669e28b623d9d28dbab4e00a7a43b9941b6028c0733e15c1048af7b8c425ed
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.