Release date:
2026-09-01 12:15:22 UTC
Description:
* SECURITY UPDATE: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)
- debian/patches/CVE-2026-54874.patch: avoid buffering the whole DTLS read buffer for a record arriving early for the next epoch (ssl/record/rec_layer_d1.c)
- CVE-2026-54874
* SECURITY UPDATE: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)
- debian/patches/CVE-2026-63072.patch: fix 8-byte out-of-bounds heap write in CMS AES-WRAP-PAD key unwrapping (crypto/cms/cms_kari.c)
- debian/patches/CVE-2026-63072-test.patch: add the upstream regression test for the AES-WRAP-PAD unwrap overflow (test/cmsapitest.c)
- CVE-2026-63072
Updated packages:
-
libssl-dev_1.1.1n-0+deb10u6+tuxcare.els6_amd64.deb
sha:70911e54bc17e486a9d902993ef5826a0f7c6518
-
libssl-doc_1.1.1n-0+deb10u6+tuxcare.els6_all.deb
sha:ed5a1cbf386e0e87090b704cda69544df155443e
-
libssl1.1_1.1.1n-0+deb10u6+tuxcare.els6_amd64.deb
sha:99f1ed5379032805d5b652bf991cc4aaf9b59c7e
-
openssl_1.1.1n-0+deb10u6+tuxcare.els6_amd64.deb
sha:69ac0240f7ca2a0b8a2ef409cc6b09b36a7dfeb6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.