Release date:
2026-09-22 13:04:42 UTC
Description:
* SECURITY UPDATE: Heap buffer overflow in CMS AES-WRAP-PAD key unwrap
- debian/patches/CVE-2026-63072.patch: size the key-unwrap output buffer
in crypto/cms/cms_kari.c for the worst case so a failed AES-WRAP-PAD
unwrap cannot write 8 bytes past the allocation, with the upstream
regression test in test/cmsapitest.c and test/recipes/80-test_cmsapi.t
- CVE-2026-63072
Updated packages:
-
libssl-dev_1.1.1w-0+deb11u8+tuxcare.els2_amd64.deb
sha:fca1da85c1a491bb6332ed9e45638d8c5e43f16c
-
libssl-doc_1.1.1w-0+deb11u8+tuxcare.els2_all.deb
sha:1de19de97a5f5fcf7ca36deb1ee181b15d64e0f4
-
libssl1.1_1.1.1w-0+deb11u8+tuxcare.els2_amd64.deb
sha:7ee51dc5c2184f42219f575cf8fc906cd0b1f7a6
-
openssl_1.1.1w-0+deb11u8+tuxcare.els2_amd64.deb
sha:908bd38b8d806a0d9946bb02f800be10d0203103
-
libssl-dev_1.1.1w-0+deb11u8+tuxcare.els2_arm64.deb
sha:3ac662c3eb5c6942bd6b8d561f975ebf6ecc904f
-
libssl1.1_1.1.1w-0+deb11u8+tuxcare.els2_arm64.deb
sha:85800223f443d75d72b5ce5247b4ce09b80be9b9
-
openssl_1.1.1w-0+deb11u8+tuxcare.els2_arm64.deb
sha:7c4a22d336838041f405eae124761afd546b4e40
-
libssl-dev_1.1.1w-0+deb11u8+tuxcare.els2_armel.deb
sha:dad76b4445ba17d48e44a6bccf72c9f96644bc7f
-
libssl1.1_1.1.1w-0+deb11u8+tuxcare.els2_armel.deb
sha:15a5632364974a30fefea09906c9350a1fc3ab63
-
openssl_1.1.1w-0+deb11u8+tuxcare.els2_armel.deb
sha:709730addae65c196b76327f0a5805aae8588a76
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.