[CLSA-2026:1785400004] openssl: Fix of CVE-2024-13176
Type:
security
Severity:
Moderate
Release date:
2026-07-30 12:15:06 UTC
Description:
- CVE-2024-13176: fix timing side-channel in ECDSA signature computation caused by the variable length of the inverted nonce
CVEs fixed:
Updated packages:
  • openssl-1.0.2k-26.el7_9.tuxcare.els12.x86_64.rpm
    sha:f42b8384ffbc2fc757b7e1e1d24c817c72ac57cf0cbe98adbc84b73fe0dc3602
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els12.i686.rpm
    sha:c23031defd9874d2f1db5c11ef96f4db277a8f4fa0f33c72ab12b14097c9a211
  • openssl-devel-1.0.2k-26.el7_9.tuxcare.els12.x86_64.rpm
    sha:8640c8ca768618147b95c2cf61166f358aebdbb93f76bad0a2153789cfde1a86
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els12.i686.rpm
    sha:402cc8c6cdfc7ce44c9932134439ebdccfdff83c054d59d6915626428379e882
  • openssl-libs-1.0.2k-26.el7_9.tuxcare.els12.x86_64.rpm
    sha:d05d31aabb9e6cc3c99c8eed50cbe3818a84019cbc9e0434ce66b4a454a6f013
  • openssl-perl-1.0.2k-26.el7_9.tuxcare.els12.x86_64.rpm
    sha:5bcf1fa4d2026cb07927262810154e1d1823e968f58e1143d9c92df7640ff4f3
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els12.i686.rpm
    sha:4f5cf06bfa75f762b5965882baaab4d7c378b92cc80684f383f9d9b36500fd5e
  • openssl-static-1.0.2k-26.el7_9.tuxcare.els12.x86_64.rpm
    sha:cba2852ace1bb6e29ce80dc346656b8ea1d96800175a277b100a8ae238c27cd5
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.