[CLSA-2026:1790082267] Fix CVE(s): CVE-2026-63072
Type:
security
Severity:
Important
Release date:
2026-09-22 13:04:42 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in CMS AES-WRAP-PAD key unwrap - debian/patches/CVE-2026-63072.patch: size the key-unwrap output buffer in crypto/cms/cms_kari.c for the worst case so a failed AES-WRAP-PAD unwrap cannot write 8 bytes past the allocation, with the upstream regression test in test/cmsapitest.c and test/recipes/80-test_cmsapi.t - CVE-2026-63072
CVEs fixed:
Updated packages:
  • libssl-dev_1.1.1w-0+deb11u8+tuxcare.els2_amd64.deb
    sha:fca1da85c1a491bb6332ed9e45638d8c5e43f16c
  • libssl-doc_1.1.1w-0+deb11u8+tuxcare.els2_all.deb
    sha:1de19de97a5f5fcf7ca36deb1ee181b15d64e0f4
  • libssl1.1_1.1.1w-0+deb11u8+tuxcare.els2_amd64.deb
    sha:7ee51dc5c2184f42219f575cf8fc906cd0b1f7a6
  • openssl_1.1.1w-0+deb11u8+tuxcare.els2_amd64.deb
    sha:908bd38b8d806a0d9946bb02f800be10d0203103
  • libssl-dev_1.1.1w-0+deb11u8+tuxcare.els2_arm64.deb
    sha:3ac662c3eb5c6942bd6b8d561f975ebf6ecc904f
  • libssl1.1_1.1.1w-0+deb11u8+tuxcare.els2_arm64.deb
    sha:85800223f443d75d72b5ce5247b4ce09b80be9b9
  • openssl_1.1.1w-0+deb11u8+tuxcare.els2_arm64.deb
    sha:7c4a22d336838041f405eae124761afd546b4e40
  • libssl-dev_1.1.1w-0+deb11u8+tuxcare.els2_armel.deb
    sha:dad76b4445ba17d48e44a6bccf72c9f96644bc7f
  • libssl1.1_1.1.1w-0+deb11u8+tuxcare.els2_armel.deb
    sha:15a5632364974a30fefea09906c9350a1fc3ab63
  • openssl_1.1.1w-0+deb11u8+tuxcare.els2_armel.deb
    sha:709730addae65c196b76327f0a5805aae8588a76
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.