[Apollo] Advisories Statistics light light Login

RLSA-2026:25237

Security Mirrored from RHSA-2026:25237
Issued at: 2026-06-13
Updated at: 2026-06-14

Synopsis

Important: openssl security update



Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

* openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing (CVE-2026-7383)

* openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption (CVE-2026-9076)

* openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. (CVE-2026-34180)

* openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181)

* openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages (CVE-2026-34182)

* openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (CVE-2026-34183)

* openssl: NULL pointer dereference in QUIC server initial packet handling (CVE-2026-42764)

* openssl: Possible NULL Dereference in Password-Based CMS Decryption (CVE-2026-42766)

* openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption (CVE-2026-42767)

* openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (CVE-2026-42768)

* openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (CVE-2026-42769)

* openssl: FFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770)

* openssl: AES-OCB IV Ignored on EVP_Cipher() Path (CVE-2026-45445)

* openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (CVE-2026-45446)

* openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2481897 2481890 2481892 2481880 2481882 2481891 2481881 2481879 2481884 2481894 2481885 2481898 2481896 2481893 2481887

CVEs

CVE-2026-34180 CVE-2026-34181 CVE-2026-34182 CVE-2026-34183 CVE-2026-42764 CVE-2026-42766 CVE-2026-42767 CVE-2026-42768 CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 CVE-2026-45446 CVE-2026-45447 CVE-2026-7383 CVE-2026-9076

Affected packages

Rocky Linux 10 ppc64le - BaseOS

openssl-libs-1:3.5.5-4.el10_2.ppc64le.rpm openssl-debuginfo-1:3.5.5-4.el10_2.ppc64le.rpm openssl-debugsource-1:3.5.5-4.el10_2.ppc64le.rpm openssl-libs-debuginfo-1:3.5.5-4.el10_2.ppc64le.rpm openssl-1:3.5.5-4.el10_2.ppc64le.rpm openssl-1:3.5.5-4.el10_2.src.rpm

Rocky Linux 10 s390x - BaseOS

openssl-debuginfo-1:3.5.5-4.el10_2.s390x.rpm openssl-libs-debuginfo-1:3.5.5-4.el10_2.s390x.rpm openssl-libs-1:3.5.5-4.el10_2.s390x.rpm openssl-1:3.5.5-4.el10_2.src.rpm openssl-debugsource-1:3.5.5-4.el10_2.s390x.rpm openssl-1:3.5.5-4.el10_2.s390x.rpm

Rocky Linux 10 x86_64 - BaseOS

openssl-debugsource-1:3.5.5-4.el10_2.x86_64.rpm openssl-debuginfo-1:3.5.5-4.el10_2.x86_64.rpm openssl-1:3.5.5-4.el10_2.src.rpm openssl-libs-debuginfo-1:3.5.5-4.el10_2.x86_64.rpm openssl-1:3.5.5-4.el10_2.x86_64.rpm openssl-libs-1:3.5.5-4.el10_2.x86_64.rpm

Rocky Linux 10 s390x - AppStream

openssl-devel-1:3.5.5-4.el10_2.s390x.rpm openssl-perl-1:3.5.5-4.el10_2.s390x.rpm

Rocky Linux 10 x86_64 - AppStream

openssl-perl-1:3.5.5-4.el10_2.x86_64.rpm openssl-devel-1:3.5.5-4.el10_2.x86_64.rpm

Rocky Linux 10 aarch64 - BaseOS

openssl-debuginfo-1:3.5.5-4.el10_2.aarch64.rpm openssl-1:3.5.5-4.el10_2.src.rpm openssl-1:3.5.5-4.el10_2.aarch64.rpm openssl-libs-debuginfo-1:3.5.5-4.el10_2.aarch64.rpm openssl-debugsource-1:3.5.5-4.el10_2.aarch64.rpm openssl-libs-1:3.5.5-4.el10_2.aarch64.rpm

Rocky Linux 10 riscv64 - BaseOS

openssl-1:3.5.5-4.el10_2.src.rpm

Rocky Linux 10 ppc64le - AppStream

openssl-perl-1:3.5.5-4.el10_2.ppc64le.rpm openssl-devel-1:3.5.5-4.el10_2.ppc64le.rpm

Rocky Linux 10 aarch64 - AppStream

openssl-perl-1:3.5.5-4.el10_2.aarch64.rpm openssl-devel-1:3.5.5-4.el10_2.aarch64.rpm