[CLSA-2026:1790035022] openssl: Fix of 2 CVEs
Type:
security
Severity:
Important
Release date:
2026-09-21 23:57:13 UTC
Description:
- rebase onto Amazon Linux 2 1.0.2k-24.amzn2.0.22 (CVE-2026-54874, CVE-2026-63072, and the "HollowByte" hardening fix); take AL2's own fix for CVE-2026-54874 and drop our openssl-1.0.2k-cve-2026-54874.patch; no new TuxCare ELS work ships here
Updated packages:
  • openssl-1.0.2k-24.amzn2.0.22.tuxcare.els1.x86_64.rpm
    sha:47a9865872a304539b2e062ff7f8b8e7441efa4508aca08a2ed9bd5e08f3e86b
  • openssl-devel-1.0.2k-24.amzn2.0.22.tuxcare.els1.x86_64.rpm
    sha:53b78f14eb17aaff0d634673752075a852005b94a54297bca20d0478526b5100
  • openssl-libs-1.0.2k-24.amzn2.0.22.tuxcare.els1.i686.rpm
    sha:463508f71e8dfce409b31b91612ed08be9766e3ea2be6c012a63d942bc2e02c0
  • openssl-libs-1.0.2k-24.amzn2.0.22.tuxcare.els1.x86_64.rpm
    sha:0523dfe1c837c864766b7f45055a2133f097d0ad813d71978d87baf6d912856c
  • openssl-perl-1.0.2k-24.amzn2.0.22.tuxcare.els1.x86_64.rpm
    sha:7e3a4bc2a83f7b76d37356df97a79287ac94306a1121c78c45b5627768e76c1b
  • openssl-static-1.0.2k-24.amzn2.0.22.tuxcare.els1.x86_64.rpm
    sha:3bd8cac640c68553cf9e7b821e732e03804530eed8213e511817f3824b79cd0b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.