EasyApache 4 25.81 — cPanel & WHM Update
EasyApache 4 release 25.81 patches ea-openssl11 on CentOS 7 against two OpenSSL flaws: a heap buffer overflow in CMS key unwrapping (CVE-2026-63072, CWE-787, CVSS 7.5) and excessive memory use when buffering DTLS records (CVE-2026-54874). CentOS 7 servers using the ea-openssl11 package should update as a priority.
Versiones afectadas
25.81
Lo que esto significa bajo una licencia de SharedLicense
A heap buffer overflow in CMS key unwrapping is the kind of memory-corruption flaw that can crash or potentially compromise processes using OpenSSL for CMS operations.
EasyApache 4 25.81
2026 September 2
Maintenance and security updates
We released updated packages for EasyApache 4.
This release patches ea-openssl11 on CentOS 7 for a heap buffer overflow in CMS key unwrapping (CVE-2026-63072) and excessive memory use when buffering DTLS records (CVE-2026-54874). It also updates ea-re2c to v4.6 and fixes three ea-podman issues: container hostnames longer than 64 bytes, systemd restart defaults for container units, and modifyacct calls being refused on accounts that own containers.
For a full list of changes, read the EasyApache 4 change log.
Preguntas frecuentes
What is CVE-2026-63072?
What is CVE-2026-54874?
Who needs this update?
How do I apply the fix?
Comprueba tu sistema en busca de vulnerabilidades
Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.
Comprueba tu sistema