[CLSA-2026:1788264233] openssl: Fix of CVE-2026-54874
Type:
security
Severity:
Important
Release date:
2026-09-01 12:04:03 UTC
Description:
- CVE-2026-54874: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch, capping per-connection memory amplification
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:f618813ccf892d18ce7ccc92e7ffe3a9dea35d82796c6a7e3621d879893b33ea
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:ca5bc78ac1f91d1903cc71b3ebb238f4112b1cce44d876ca0585a6889f1fa762
  • openssl-devel-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:cb922093540805e3c97d4e52b6b314fcddb40906ffeaed5570a72dd5c07efb56
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:eb44b83c7dfd2b9cb8bddfd39efbfddc6cd12aae910e55acf4bbf31ccde051c7
  • openssl-libs-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:5c0d8cc9a9d2765a5755d495e31a4dbf0c2d7b5b557e768d9f085c4aa010f621
  • openssl-perl-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:f99fcd4dbbc2fe4c3e7d0287036e311ef233f59abe99ee0ac6b47e95e568df81
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els3.i686.rpm
    sha:3ad3d1a5f90f5be2337454a331b3d8da880242c3a17a308d40c411b4ad31fce7
  • openssl-static-1.0.2k-26.0.1.el7_9.tuxcare.els3.x86_64.rpm
    sha:30faa9f8f3b8826d38d438a3ab1844b42e8cf02cff814e1af852d289dec99a5f
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.