Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:35869: Important: compat-openssl11 security update

Two high-severity vulnerabilities in OpenSSL, CVE-2026-28390 (CVSS 7.5) and CVE-2026-45447 (CVSS 8.8), affect the `compat-openssl11` library for RHEL 9.6 EUS. The flaws consist of a NULL pointer dereference in CMS EnvelopedData processing leading to denial of service, and a heap use-after-free in `PKCS7_verify()`. The NVD data indicates affected versions are OpenSSL 1.1.1 up to, but not including, versions 1.1.1zg and 1.1.1zh, respectively.
Read Full Article →

Red Hat Product Errata RHSA-2026:35869 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35869 - Security Advisory Overview Updated Packages Synopsis Important: compat-openssl11 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for compat-openssl11 is now available for Red Hat Enterprise Linux 9.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases. Security Fix(es): openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 x86_64 Red Hat Enterprise Linux Server - AUS 9.6 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.6 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.6 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.6 s390x Fixes BZ - 2456314 - CVE-2026-28390 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing BZ - 2481898 - CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVEs CVE-2026-28390 CVE-2026-45447 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf x86_64 compat-openssl11-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 45ba317a75ab60f4ca472765521699b22dd0532c9c2ff7bdcf7cf714f5d0027f compat-openssl11-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 71562cfa1f9f99dd3a52bfeff1794757693f122c0990a261c22a51a7f20ddc8a compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 5093a1ed18691ce6d52c48d9b9df8324ac4f0643759d02afb5f961f6a8b9bf8d compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 47c83f31d66f358fc8b63d6908c8fb4f52b213cc0a787bd0f15627bdb0bd1340 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 56632b0ac5f9114d1210aa1e925e8757f98a621cf18f091ae6a7b1672898424e compat-openssl11-debugsource-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 91ec0c2b3ddc5415ee0e7331a5af9c9e9160d5004ee5cbbac490524c6c6e6d68 Red Hat Enterprise Linux Server - AUS 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf x86_64 compat-openssl11-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 45ba317a75ab60f4ca472765521699b22dd0532c9c2ff7bdcf7cf714f5d0027f compat-openssl11-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 71562cfa1f9f99dd3a52bfeff1794757693f122c0990a261c22a51a7f20ddc8a compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 5093a1ed18691ce6d52c48d9b9df8324ac4f0643759d02afb5f961f6a8b9bf8d compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 47c83f31d66f358fc8b63d6908c8fb4f52b213cc0a787bd0f15627bdb0bd1340 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 56632b0ac5f9114d1210aa1e925e8757f98a621cf18f091ae6a7b1672898424e compat-openssl11-debugsource-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 91ec0c2b3ddc5415ee0e7331a5af9c9e9160d5004ee5cbbac490524c6c6e6d68 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf s390x compat-openssl11-1.1.1k-5.el9_6.3.s390x.rpm SHA-256: e151440331e4dabdca5cc0c13f0d6e73e164caabe3e15e62b94f195dcae54f3a compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.s390x.rpm SHA-256: a4aae28e7599d7edb3eedab51f1e5128d9464c381d7cee31c6d1a77635b51567 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.s390x.rpm SHA-256: e75fe2bd106d2219ca84e56952d58cffb2c82c64b00f4370867443834855012b Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf ppc64le compat-openssl11-1.1.1k-5.el9_6.3.ppc64le.rpm SHA-256: ea0ed5a306d1cf407a6a2a61fa8819e72711c63b35d037b88f4b6a096271b488 compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.ppc64le.rpm SHA-256: 7197e894e93a88b60400a5c3381d0f5ce41fd79b45768d7cc1d5bd2fae9376f8 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.ppc64le.rpm SHA-256: 227a468c0962e535eee141570f02ee4e8380e6a6c834995c1bd2649912b4e06f Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf aarch64 compat-openssl11-1.1.1k-5.el9_6.3.aarch64.rpm SHA-256: 8a027f7a8e1866bb17bd3b14df0b0819597da11acc656649490f803c8b517e3f compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.aarch64.rpm SHA-256: c6f47c5d9f4e65fe34c79a049de43fbdd7d6ee5b0046606a49d1b2d63f0c0539 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.aarch64.rpm SHA-256: f2ce5b3f2b0fe34bfa19e8a9ed6c232502c30d4955334841627f3e0375cbb81d Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf ppc64le compat-openssl11-1.1.1k-5.el9_6.3.ppc64le.rpm SHA-256: ea0ed5a306d1cf407a6a2a61fa8819e72711c63b35d037b88f4b6a096271b488 compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.ppc64le.rpm SHA-256: 7197e894e93a88b60400a5c3381d0f5ce41fd79b45768d7cc1d5bd2fae9376f8 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.ppc64le.rpm SHA-256: 227a468c0962e535eee141570f02ee4e8380e6a6c834995c1bd2649912b4e06f Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf x86_64 compat-openssl11-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 45ba317a75ab60f4ca472765521699b22dd0532c9c2ff7bdcf7cf714f5d0027f compat-openssl11-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 71562cfa1f9f99dd3a52bfeff1794757693f122c0990a261c22a51a7f20ddc8a compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 5093a1ed18691ce6d52c48d9b9df8324ac4f0643759d02afb5f961f6a8b9bf8d compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 47c83f31d66f358fc8b63d6908c8fb4f52b213cc0a787bd0f15627bdb0bd1340 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 56632b0ac5f9114d1210aa1e925e8757f98a621cf18f091ae6a7b1672898424e compat-openssl11-debugsource-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 91ec0c2b3ddc5415ee0e7331a5af9c9e9160d5004ee5cbbac490524c6c6e6d68 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf aarch64 compat-openssl11-1.1.1k-5.el9_6.3.aarch64.rpm SHA-256: 8a027f7a8e1866bb17bd3b14df0b0819597da11acc656649490f803c8b517e3f compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.aarch64.rpm SHA-256: c6f47c5d9f4e65fe34c79a049de43fbdd7d6ee5b0046606a49d1b2d63f0c0539 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.aarch64.rpm SHA-256: f2ce5b3f2b0fe34bfa19e8a9ed6c232502c30d4955334841627f3e0375cbb81d Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf s390x compat-openssl11-1.1.1k-5.el9_6.3.s390x.rpm SHA-256: e151440331e4dabdca5cc0c13f0d6e73e164caabe3e15e62b94f195dcae54f3a compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.s390x.rpm SHA-256: a4aae28e7599d7edb3eedab51f1e5128d9464c381d7cee31c6d1a77635b51567 compat-openssl11-debugsource-1.1.1k-5.el9_6.3.s390x.rpm SHA-256: e75fe2bd106d2219ca84e56952d58cffb2c82c64b00f4370867443834855012b Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.6 SRPM compat-openssl11-1.1.1k-5.el9_6.3.src.rpm SHA-256: 022a51ea3f64ffce86df0f053560930135a0cf72a9cd8880f4edcd160b3b99cf x86_64 compat-openssl11-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 45ba317a75ab60f4ca472765521699b22dd0532c9c2ff7bdcf7cf714f5d0027f compat-openssl11-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 71562cfa1f9f99dd3a52bfeff1794757693f122c0990a261c22a51a7f20ddc8a compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.i686.rpm SHA-256: 5093a1ed18691ce6d52c48d9b9df8324ac4f0643759d02afb5f961f6a8b9bf8d compat-openssl11-debuginfo-1.1.1k-5.el9_6.3.x86_64.rpm SHA-256: 47c83f31d66f358fc8b63d6908c8fb4f52b213cc0a787bd0f15627bdb0bd1340 compat-openssl11-debugsource-1.1.1k-5

Share this article