Issued at: 2026-06-05
Updated at: 2026-06-05
Synopsis
Moderate: compat-openssl10 security update
Description
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries and is provided for compatibility with previous releases and software that does not support compilation with OpenSSL-1.1.
Security Fix(es):
* openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected products
Rocky Linux 8 aarch64
Rocky Linux 8 x86_64
Fixes
2456314
CVEs
CVE-2026-28390
Affected packages
Rocky Linux 8 aarch64 - AppStream
compat-openssl10-1:1.0.2o-4.el8_10.2.aarch64.rpm
compat-openssl10-1:1.0.2o-4.el8_10.2.src.rpm
compat-openssl10-debuginfo-1:1.0.2o-4.el8_10.2.aarch64.rpm
compat-openssl10-debugsource-1:1.0.2o-4.el8_10.2.aarch64.rpm
Rocky Linux 8 x86_64 - AppStream
compat-openssl10-1:1.0.2o-4.el8_10.2.i686.rpm
compat-openssl10-1:1.0.2o-4.el8_10.2.src.rpm
compat-openssl10-1:1.0.2o-4.el8_10.2.x86_64.rpm
compat-openssl10-debuginfo-1:1.0.2o-4.el8_10.2.i686.rpm
compat-openssl10-debuginfo-1:1.0.2o-4.el8_10.2.x86_64.rpm
compat-openssl10-debugsource-1:1.0.2o-4.el8_10.2.i686.rpm
compat-openssl10-debugsource-1:1.0.2o-4.el8_10.2.x86_64.rpm