- What: Security update for compat-openssl10 in Red Hat Enterprise Linux
- Impact: Systems using OpenSSL may be vulnerable to unspecified security issues
Red Hat Product Errata RHSA-2026:47096 - Security Advisory Issued: 2026-07-28 Updated: 2026-07-28 RHSA-2026:47096 - Security Advisory Overview Updated Packages Synopsis Moderate: compat-openssl10 security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for compat-openssl10 is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries and is provided for compatibility with previous releases and software that does not support compilation with OpenSSL-1.1. Security Fix(es): openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2456314 - CVE-2026-28390 openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing CVEs CVE-2026-28390 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.4 SRPM compat-openssl10-1.0.2o-3.el8_4.1.src.rpm SHA-256: 51222559510b24375dcb07fc94f7efe75bb229167a98cf33cf92aff21052a1ce x86_64 compat-openssl10-1.0.2o-3.el8_4.1.i686.rpm SHA-256: 0a4790713aeed75398a5598b3d53cca114e2c7b8d3a2273fb8caa52e64545be7 compat-openssl10-1.0.2o-3.el8_4.1.x86_64.rpm SHA-256: ef644f00af33061f16ea7bfc2e684dfebd83f4ec26951fc9d554670c8eb8522c compat-openssl10-debuginfo-1.0.2o-3.el8_4.1.i686.rpm SHA-256: eed373bd499463aaf7766ded573d600689b113deba7c46dcd12ecd99c99ed415 compat-openssl10-debuginfo-1.0.2o-3.el8_4.1.x86_64.rpm SHA-256: 251e88a19b8446416a6e74afcadd3ffebc127f06a8aef7617396a101ec18c892 compat-openssl10-debugsource-1.0.2o-3.el8_4.1.i686.rpm SHA-256: 229bda5fc205674e7ac354d1f0ea1f88164feb0143684713d6658dfef3cb8bd9 compat-openssl10-debugsource-1.0.2o-3.el8_4.1.x86_64.rpm SHA-256: 291c071d5ef3866fd468a7eaeaac0f6cc6ae2835ee3ae6547bf9344ebc661e4e Red Hat Enterprise Linux Server - AUS 8.4 SRPM compat-openssl10-1.0.2o-3.el8_4.1.src.rpm SHA-256: 51222559510b24375dcb07fc94f7efe75bb229167a98cf33cf92aff21052a1ce x86_64 compat-openssl10-1.0.2o-3.el8_4.1.i686.rpm SHA-256: 0a4790713aeed75398a5598b3d53cca114e2c7b8d3a2273fb8caa52e64545be7 compat-openssl10-1.0.2o-3.el8_4.1.x86_64.rpm SHA-256: ef644f00af33061f16ea7bfc2e684dfebd83f4ec26951fc9d554670c8eb8522c compat-openssl10-debuginfo-1.0.2o-3.el8_4.1.i686.rpm SHA-256: eed373bd499463aaf7766ded573d600689b113deba7c46dcd12ecd99c99ed415 compat-openssl10-debuginfo-1.0.2o-3.el8_4.1.x86_64.rpm SHA-256: 251e88a19b8446416a6e74afcadd3ffebc127f06a8aef7617396a101ec18c892 compat-openssl10-debugsource-1.0.2o-3.el8_4.1.i686.rpm SHA-256: 229bda5fc205674e7ac354d1f0ea1f88164feb0143684713d6658dfef3cb8bd9 compat-openssl10-debugsource-1.0.2o-3.el8_4.1.x86_64.rpm SHA-256: 291c071d5ef3866fd468a7eaeaac0f6cc6ae2835ee3ae6547bf9344ebc661e4e The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .