[Apollo] Advisories Statistics light light Login

RLSA-2026:67165

Security Mirrored from RHSA-2026:67165
Issued at: 2026-09-15
Updated at: 2026-09-16

Advisory content derived from Red Hat RHSA-2026:67165, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: openssl security, bug fix, and enhancement update



Description

OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.

Security Fix(es):

* openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server (CVE-2026-14456)

* openssl: QUIC server may trigger double free when processing INITIAL packet (CVE-2026-18798)

* openssl: heap buffer overflow in CMS key unwrapping (CVE-2026-63072)

* openssl: invalid pointer dereference in CMP server via crafted protectionAlg (CVE-2026-63076)

* openssl: RPK server signature algorithm selection can dereference a missing certificate (CVE-2026-14457)

* openssl: excessive memory use buffering DTLS records for a future epoch (CVE-2026-54874)

* openssl: untrusted sender DN used as format string in CMP response validation (CVE-2026-63073)

* openssl: CMP indefinite cache growth of ExtraCerts (CVE-2026-63074)

* openssl: QUIC ACK-only packet retention can cause memory exhaustion (CVE-2026-63075)

Bug Fix(es) and Enhancement(s):

* openssl: HollowByte remote memory-exhaustion DoS fix may be missing [Rocky Linux 9.8.z] (JIRA:Rocky Linux-232828)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 9 aarch64 Rocky Linux 9 ppc64le Rocky Linux 9 s390x Rocky Linux 9 x86_64

Fixes

2515348 2517559 2517560 2517561 2517562 2517564 2517565 2517566 2517570

CVEs

CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076

Affected packages

Rocky Linux 9 x86_64 - AppStream

openssl-devel-1:3.5.8-1.el9_8.x86_64.rpm openssl-devel-1:3.5.8-1.el9_8.i686.rpm openssl-perl-1:3.5.8-1.el9_8.x86_64.rpm

Rocky Linux 9 aarch64 - BaseOS

openssl-1:3.5.8-1.el9_8.aarch64.rpm openssl-1:3.5.8-1.el9_8.src.rpm openssl-debuginfo-1:3.5.8-1.el9_8.aarch64.rpm openssl-debugsource-1:3.5.8-1.el9_8.aarch64.rpm openssl-libs-1:3.5.8-1.el9_8.aarch64.rpm openssl-libs-debuginfo-1:3.5.8-1.el9_8.aarch64.rpm

Rocky Linux 9 ppc64le - BaseOS

openssl-1:3.5.8-1.el9_8.ppc64le.rpm openssl-1:3.5.8-1.el9_8.src.rpm openssl-debuginfo-1:3.5.8-1.el9_8.ppc64le.rpm openssl-debugsource-1:3.5.8-1.el9_8.ppc64le.rpm openssl-libs-1:3.5.8-1.el9_8.ppc64le.rpm openssl-libs-debuginfo-1:3.5.8-1.el9_8.ppc64le.rpm

Rocky Linux 9 s390x - BaseOS

openssl-1:3.5.8-1.el9_8.s390x.rpm openssl-1:3.5.8-1.el9_8.src.rpm openssl-debuginfo-1:3.5.8-1.el9_8.s390x.rpm openssl-debugsource-1:3.5.8-1.el9_8.s390x.rpm openssl-libs-1:3.5.8-1.el9_8.s390x.rpm openssl-libs-debuginfo-1:3.5.8-1.el9_8.s390x.rpm

Rocky Linux 9 x86_64 - BaseOS

openssl-1:3.5.8-1.el9_8.src.rpm openssl-1:3.5.8-1.el9_8.x86_64.rpm openssl-debuginfo-1:3.5.8-1.el9_8.i686.rpm openssl-debuginfo-1:3.5.8-1.el9_8.x86_64.rpm openssl-debugsource-1:3.5.8-1.el9_8.i686.rpm openssl-debugsource-1:3.5.8-1.el9_8.x86_64.rpm openssl-libs-1:3.5.8-1.el9_8.i686.rpm openssl-libs-1:3.5.8-1.el9_8.x86_64.rpm openssl-libs-debuginfo-1:3.5.8-1.el9_8.i686.rpm openssl-libs-debuginfo-1:3.5.8-1.el9_8.x86_64.rpm

Rocky Linux 9 aarch64 - AppStream

openssl-devel-1:3.5.8-1.el9_8.aarch64.rpm openssl-perl-1:3.5.8-1.el9_8.aarch64.rpm

Rocky Linux 9 ppc64le - AppStream

openssl-devel-1:3.5.8-1.el9_8.ppc64le.rpm openssl-perl-1:3.5.8-1.el9_8.ppc64le.rpm

Rocky Linux 9 s390x - AppStream

openssl-devel-1:3.5.8-1.el9_8.s390x.rpm openssl-perl-1:3.5.8-1.el9_8.s390x.rpm