[CLSA-2026:1775148645] Fix CVE(s): CVE-2023-5678, CVE-2024-0727
Type:
security
Severity:
Moderate
Release date:
2026-04-02 16:50:50 UTC
Description:
* SECURITY UPDATE: excessive time spent in DH check/generation with large Q - debian/patches/openssl-1.1.1-cve-2023-5678.patch: add bounds checks for excessively large Q parameter in DH_check_pub_key() and DH_generate_key() - CVE-2023-5678 * SECURITY UPDATE: PKCS12 decoding crashes due to NULL pointer dereference - debian/patches/openssl-1.1.1-cve-2024-0727.patch: add NULL checks where ContentInfo data can be NULL in PKCS12/PKCS7 parsing functions - CVE-2024-0727
Updated packages:
  • alt-openssl_1.1.1w-3.2_amd64.deb
    sha:9959cd856a9d5ca3af687a89ce83af045d531128
  • alt-openssl-dev_1.1.1w-3.2_amd64.deb
    sha:16d967267d557b96d41f7f41d669c1000103f1b0
  • alt-openssl-doc_1.1.1w-3.2_all.deb
    sha:9f966e319e89f767686dedb938adcd5bd7c0387d
  • alt-openssl-libs_1.1.1w-3.2_amd64.deb
    sha:0f842c9af5821d7624ad918eaf12286316397bc8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.