Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25239: Important: openssl security update

This Red Hat security advisory addresses multiple vulnerabilities in OpenSSL for RHEL 9, rated Important, including a heap buffer overflow in Unicode output sizing (CVE-2026-7383, CVSS 8.1), a denial of service from a heap out-of-bounds read in CMS decryption (CVE-2026-9076, CVSS 7.5), and a heap buffer over-read in ASN.1 decoding (CVE-2026-34180, CVSS 7.5). The update provides fixes for these and other issues such as memory growth in QUIC handlers and NULL pointer dereferences. Affected systems should apply the openssl update via the referenced Red Hat channels.
Read Full Article →

Red Hat Product Errata RHSA-2026:25239 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25239 - Security Advisory Overview Updated Packages Synopsis Important: openssl security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for openssl is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing (CVE-2026-7383) openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption (CVE-2026-9076) openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. (CVE-2026-34180) openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181) openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages (CVE-2026-34182) openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (CVE-2026-34183) openssl: NULL pointer dereference in QUIC server initial packet handling (CVE-2026-42764) openssl: Possible NULL Dereference in Password-Based CMS Decryption (CVE-2026-42766) openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption (CVE-2026-42767) openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (CVE-2026-42768) openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (CVE-2026-42769) openssl: FFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770) openssl: AES-OCB IV Ignored on EVP_Cipher() Path (CVE-2026-45445) openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (CVE-2026-45446) openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2481879 - CVE-2026-7383 openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing BZ - 2481880 - CVE-2026-9076 openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption BZ - 2481881 - CVE-2026-34180 openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. BZ - 2481882 - CVE-2026-34181 openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys BZ - 2481884 - CVE-2026-34182 openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages BZ - 2481885 - CVE-2026-34183 openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler BZ - 2481887 - CVE-2026-42764 openssl: NULL pointer dereference in QUIC server initial packet handling BZ - 2481890 - CVE-2026-42766 openssl: Possible NULL Dereference in Password-Based CMS Decryption BZ - 2481891 - CVE-2026-42767 openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption BZ - 2481892 - CVE-2026-42768 openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() BZ - 2481893 - CVE-2026-42769 openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate BZ - 2481894 - CVE-2026-42770 openssl: FFC-DH Peer Validation Uses Attacker-Supplied q BZ - 2481896 - CVE-2026-45445 openssl: AES-OCB IV Ignored on EVP_Cipher() Path BZ - 2481897 - CVE-2026-45446 openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes BZ - 2481898 - CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVEs CVE-2026-7383 CVE-2026-9076 CVE-2026-34180 CVE-2026-34181 CVE-2026-34182 CVE-2026-34183 CVE-2026-42764 CVE-2026-42766 CVE-2026-42767 CVE-2026-42768 CVE-2026-42769 CVE-2026-42770 CVE-2026-45445 CVE-2026-45446 CVE-2026-45447 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM openssl-3.5.5-4.el9_8.src.rpm SHA-256: 7f1e764394ad2e1a4915fef182edbaad643dab6b59cbd52679a0962b26cb5d36 x86_64 openssl-3.5.5-4.el9_8.x86_64.rpm SHA-256: e0e2c1f901d3f6245ff43f194ac11ba133cf99c630307239722c07a2282a1356 openssl-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 1e851098d026edd5fd09dc9ffa552a139383bea91ab348233f185f4a6aea2cfa openssl-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 1e851098d026edd5fd09dc9ffa552a139383bea91ab348233f185f4a6aea2cfa openssl-debuginfo-3.5.5-4.el9_8.x86_64.rpm SHA-256: 75053366cabb5574b31426bc2621e5c3e7d7a8c8e9ae24818c4ee25e7b255536 openssl-debuginfo-3.5.5-4.el9_8.x86_64.rpm SHA-256: 75053366cabb5574b31426bc2621e5c3e7d7a8c8e9ae24818c4ee25e7b255536 openssl-debugsource-3.5.5-4.el9_8.i686.rpm SHA-256: 2fb62d540eb0ced24c2af078b44d70937d5411b594ff6be7b77fa819195e5245 openssl-debugsource-3.5.5-4.el9_8.i686.rpm SHA-256: 2fb62d540eb0ced24c2af078b44d70937d5411b594ff6be7b77fa819195e5245 openssl-debugsource-3.5.5-4.el9_8.x86_64.rpm SHA-256: 825d0020559ecdf3359c61629784d6cc07eaf93dd7e8805346ca3324d1320bb4 openssl-debugsource-3.5.5-4.el9_8.x86_64.rpm SHA-256: 825d0020559ecdf3359c61629784d6cc07eaf93dd7e8805346ca3324d1320bb4 openssl-devel-3.5.5-4.el9_8.i686.rpm SHA-256: 09eb6eeb087212ae884fa510509f3087df3184ef3a7f671eae0fd5b2f84c775c openssl-devel-3.5.5-4.el9_8.x86_64.rpm SHA-256: b8bd95180ea457da07e0bf5e33c5425703df34ba25426266baec5336e18e5dea openssl-libs-3.5.5-4.el9_8.i686.rpm SHA-256: 5e28c04bf396ae9015d14caaa9bb8fbf21920ce62e3dc3d62b9c004c50093128 openssl-libs-3.5.5-4.el9_8.x86_64.rpm SHA-256: 126c17e907e1f6cbbd3989a478e933a74d5508e70b8983b0f6a94e7fd2a903e6 openssl-libs-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 63f5c21d6043078d1cf63c556c10995842f33e6bd507df7480c9a61f5fb2bc03 openssl-libs-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 63f5c21d6043078d1cf63c556c10995842f33e6bd507df7480c9a61f5fb2bc03 openssl-libs-debuginfo-3.5.5-4.el9_8.x86_64.rpm SHA-256: 623e990d0477f9147c6a6e7560b999dca313b06372b6b8613252687d546e7e5a openssl-libs-debuginfo-3.5.5-4.el9_8.x86_64.rpm SHA-256: 623e990d0477f9147c6a6e7560b999dca313b06372b6b8613252687d546e7e5a openssl-perl-3.5.5-4.el9_8.x86_64.rpm SHA-256: 625ce2b817d83086067aa395a7e4e67247c9f3a37c13e5cf7c86579a89920b59 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM openssl-3.5.5-4.el9_8.src.rpm SHA-256: 7f1e764394ad2e1a4915fef182edbaad643dab6b59cbd52679a0962b26cb5d36 x86_64 openssl-3.5.5-4.el9_8.x86_64.rpm SHA-256: e0e2c1f901d3f6245ff43f194ac11ba133cf99c630307239722c07a2282a1356 openssl-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 1e851098d026edd5fd09dc9ffa552a139383bea91ab348233f185f4a6aea2cfa openssl-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 1e851098d026edd5fd09dc9ffa552a139383bea91ab348233f185f4a6aea2cfa openssl-debuginfo-3.5.5-4.el9_8.x86_64.rpm SHA-256: 75053366cabb5574b31426bc2621e5c3e7d7a8c8e9ae24818c4ee25e7b255536 openssl-debuginfo-3.5.5-4.el9_8.x86_64.rpm SHA-256: 75053366cabb5574b31426bc2621e5c3e7d7a8c8e9ae24818c4ee25e7b255536 openssl-debugsource-3.5.5-4.el9_8.i686.rpm SHA-256: 2fb62d540eb0ced24c2af078b44d70937d5411b594ff6be7b77fa819195e5245 openssl-debugsource-3.5.5-4.el9_8.i686.rpm SHA-256: 2fb62d540eb0ced24c2af078b44d70937d5411b594ff6be7b77fa819195e5245 openssl-debugsource-3.5.5-4.el9_8.x86_64.rpm SHA-256: 825d0020559ecdf3359c61629784d6cc07eaf93dd7e8805346ca3324d1320bb4 openssl-debugsource-3.5.5-4.el9_8.x86_64.rpm SHA-256: 825d0020559ecdf3359c61629784d6cc07eaf93dd7e8805346ca3324d1320bb4 openssl-devel-3.5.5-4.el9_8.i686.rpm SHA-256: 09eb6eeb087212ae884fa510509f3087df3184ef3a7f671eae0fd5b2f84c775c openssl-devel-3.5.5-4.el9_8.x86_64.rpm SHA-256: b8bd95180ea457da07e0bf5e33c5425703df34ba25426266baec5336e18e5dea openssl-libs-3.5.5-4.el9_8.i686.rpm SHA-256: 5e28c04bf396ae9015d14caaa9bb8fbf21920ce62e3dc3d62b9c004c50093128 openssl-libs-3.5.5-4.el9_8.x86_64.rpm SHA-256: 126c17e907e1f6cbbd3989a478e933a74d5508e70b8983b0f6a94e7fd2a903e6 openssl-libs-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 63f5c21d6043078d1cf63c556c10995842f33e6bd507df7480c9a61f5fb2bc03 openssl-libs-debuginfo-3.5.5-4.el9_8.i686.rpm SHA-256: 63f5c21d6043078d1cf63c556c10995842f33e6bd507df7480c9a61f5fb2bc03 openssl-libs-debuginfo-3.5.5-4.el9_8.x86_6

Share this article