[Apollo] Advisories Statistics light light Login

RLSA-2026:67154

Security Mirrored from RHSA-2026:67154
Issued at: 2026-09-15
Updated at: 2026-09-16

Advisory content derived from Red Hat RHSA-2026:67154, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: openssl security, bug fix, and enhancement update



Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)

* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)

* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)

* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)

* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)

* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)

* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)

* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)

* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)

Bug Fix(es) and Enhancement(s):

* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 10.2.z] (JIRA:Rocky Linux-212362)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 ppc64le Rocky Linux 10 riscv64 Rocky Linux 10 s390x Rocky Linux 10 x86_64

Fixes

2515348 2517559 2517560 2517561 2517562 2517564 2517565 2517566 2517570

CVEs

CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076

Affected packages

Rocky Linux 10 s390x - BaseOS

openssl-1:3.5.8-1.el10_2.src.rpm openssl-libs-1:3.5.8-1.el10_2.s390x.rpm openssl-libs-debuginfo-1:3.5.8-1.el10_2.s390x.rpm openssl-debuginfo-1:3.5.8-1.el10_2.s390x.rpm openssl-debugsource-1:3.5.8-1.el10_2.s390x.rpm openssl-1:3.5.8-1.el10_2.s390x.rpm

Rocky Linux 10 x86_64 - BaseOS

openssl-1:3.5.8-1.el10_2.src.rpm openssl-libs-1:3.5.8-1.el10_2.x86_64.rpm openssl-debugsource-1:3.5.8-1.el10_2.x86_64.rpm openssl-libs-debuginfo-1:3.5.8-1.el10_2.x86_64.rpm openssl-1:3.5.8-1.el10_2.x86_64.rpm openssl-debuginfo-1:3.5.8-1.el10_2.x86_64.rpm

Rocky Linux 10 ppc64le - AppStream

openssl-perl-1:3.5.8-1.el10_2.ppc64le.rpm openssl-devel-1:3.5.8-1.el10_2.ppc64le.rpm

Rocky Linux 10 ppc64le - BaseOS

openssl-libs-debuginfo-1:3.5.8-1.el10_2.ppc64le.rpm openssl-libs-1:3.5.8-1.el10_2.ppc64le.rpm openssl-1:3.5.8-1.el10_2.ppc64le.rpm openssl-1:3.5.8-1.el10_2.src.rpm openssl-debuginfo-1:3.5.8-1.el10_2.ppc64le.rpm openssl-debugsource-1:3.5.8-1.el10_2.ppc64le.rpm

Rocky Linux 10 x86_64 - AppStream

openssl-devel-1:3.5.8-1.el10_2.x86_64.rpm openssl-perl-1:3.5.8-1.el10_2.x86_64.rpm

Rocky Linux 10 s390x - AppStream

openssl-devel-1:3.5.8-1.el10_2.s390x.rpm openssl-perl-1:3.5.8-1.el10_2.s390x.rpm

Rocky Linux 10 aarch64 - BaseOS

openssl-1:3.5.8-1.el10_2.src.rpm openssl-1:3.5.8-1.el10_2.aarch64.rpm openssl-libs-1:3.5.8-1.el10_2.aarch64.rpm openssl-debuginfo-1:3.5.8-1.el10_2.aarch64.rpm openssl-libs-debuginfo-1:3.5.8-1.el10_2.aarch64.rpm openssl-debugsource-1:3.5.8-1.el10_2.aarch64.rpm

Rocky Linux 10 riscv64 - BaseOS

openssl-1:3.5.8-1.el10_2.src.rpm

Rocky Linux 10 aarch64 - AppStream

openssl-devel-1:3.5.8-1.el10_2.aarch64.rpm openssl-perl-1:3.5.8-1.el10_2.aarch64.rpm