- What: Security update for OpenSSL in Red Hat Enterprise Linux
- Impact: Systems using OpenSSL may be vulnerable to SSL selection issues
Red Hat Product Errata RHSA-2026:66524 - Security Advisory Issued: 2026-09-10 Updated: 2026-09-10 RHSA-2026:66524 - Security Advisory Overview Updated Packages Synopsis Important: openssl security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for openssl is now available for Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSION. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): openssl: SSL_select_next_proto buffer overread (CVE-2024-5535) openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447) Bug Fix(es) and Enhancement(s): Openssl builds failing in rhel6 due to failing tests (JIRA:RHEL-184262) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 x86_64 Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 i386 Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 s390x Fixes BZ - 2294581 - CVE-2024-5535 openssl: SSL_select_next_proto buffer overread BZ - 2481898 - CVE-2026-45447 openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() CVEs CVE-2024-5535 CVE-2026-45447 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 SRPM openssl-1.0.1e-61.el6_10.1.src.rpm SHA-256: c53063e4a1b6b7f965aa1982a1975fbffaa81303bc7e4151e9bd3f916b88cc30 x86_64 openssl-1.0.1e-61.el6_10.1.i686.rpm SHA-256: 2ea295af10b465179323127e17aae98763975fc58ff76098bb86e9288df88152 openssl-1.0.1e-61.el6_10.1.x86_64.rpm SHA-256: 6da7a2417e9a7410ee2b21507f7356bc8833f885af1512f9144378a87efdd305 openssl-debuginfo-1.0.1e-61.el6_10.1.i686.rpm SHA-256: 72f74d933483df80f44eca5b7a68990b95a9ce5c783ae7271b013f5be853982f openssl-debuginfo-1.0.1e-61.el6_10.1.x86_64.rpm SHA-256: 39e1df7b5b0003f6442e95650eb5eac89392db6f3ef1bf7a62a8c3bb5ffd8c2e openssl-debuginfo-1.0.1e-61.el6_10.1.x86_64.rpm SHA-256: 39e1df7b5b0003f6442e95650eb5eac89392db6f3ef1bf7a62a8c3bb5ffd8c2e openssl-devel-1.0.1e-61.el6_10.1.i686.rpm SHA-256: bf7dfb187d1dd4518ed74737e2cb85d214c0755895160e9cf95bac9aacb277b2 openssl-devel-1.0.1e-61.el6_10.1.x86_64.rpm SHA-256: 82b12bde6d4a844a8226ce5732d213bb1e1dfffe4b87515cab6bbb42fbd5b7b1 openssl-perl-1.0.1e-61.el6_10.1.x86_64.rpm SHA-256: 48e97ffeb36412e0e706a366415cea7be64cecfc40633c5f3cba4ed6cca4e538 openssl-static-1.0.1e-61.el6_10.1.x86_64.rpm SHA-256: a61b3fc9741f45518a5a9c0d35a400852701f3406f3b6b3ffc5d92d6ca52ddd0 i386 openssl-1.0.1e-61.el6_10.1.i686.rpm SHA-256: 2ea295af10b465179323127e17aae98763975fc58ff76098bb86e9288df88152 openssl-debuginfo-1.0.1e-61.el6_10.1.i686.rpm SHA-256: 72f74d933483df80f44eca5b7a68990b95a9ce5c783ae7271b013f5be853982f openssl-debuginfo-1.0.1e-61.el6_10.1.i686.rpm SHA-256: 72f74d933483df80f44eca5b7a68990b95a9ce5c783ae7271b013f5be853982f openssl-devel-1.0.1e-61.el6_10.1.i686.rpm SHA-256: bf7dfb187d1dd4518ed74737e2cb85d214c0755895160e9cf95bac9aacb277b2 openssl-perl-1.0.1e-61.el6_10.1.i686.rpm SHA-256: d3ea4f4445b17396522188660b0daa7f8a12ec6f23e77c8fc3a57189c4df953a openssl-static-1.0.1e-61.el6_10.1.i686.rpm SHA-256: 5f598e843f19ea28c8fac6cb04ea78201f5de925d1b0994f1b731f128052d6e6 Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 SRPM openssl-1.0.1e-61.el6_10.1.src.rpm SHA-256: c53063e4a1b6b7f965aa1982a1975fbffaa81303bc7e4151e9bd3f916b88cc30 s390x openssl-1.0.1e-61.el6_10.1.s390.rpm SHA-256: 47f4f0cfb7d4bfa9365e68ca7e2e58b98db85166667ab5b6cdb35c5de17c2957 openssl-1.0.1e-61.el6_10.1.s390x.rpm SHA-256: ce162c6d9733f2a334cb8e6b703aa996b9da0710a187d0196c23d1d69f60bada openssl-debuginfo-1.0.1e-61.el6_10.1.s390.rpm SHA-256: 2aa25f661a48f196cf8a18e086147cab250d77a2037e80a31882d35715990cb5 openssl-debuginfo-1.0.1e-61.el6_10.1.s390x.rpm SHA-256: 28154d8902ee7ecd374d68d2ecc8d6b182c5a460fa96b4d5538c378054fc4a14 openssl-debuginfo-1.0.1e-61.el6_10.1.s390x.rpm SHA-256: 28154d8902ee7ecd374d68d2ecc8d6b182c5a460fa96b4d5538c378054fc4a14 openssl-devel-1.0.1e-61.el6_10.1.s390.rpm SHA-256: 0ea43d0f3d358f3699e46711719890c3acbf69cc60c1740839c11b6d46992826 openssl-devel-1.0.1e-61.el6_10.1.s390x.rpm SHA-256: 4cb6e5acda4a5c9d773f7148f08314b4877800f3ea1ebd3ae0e7e6ff1ab197e3 openssl-perl-1.0.1e-61.el6_10.1.s390x.rpm SHA-256: 1e57d2e6dc74fb9f283ebf86fcb601c29bd9ae209f9bab91f5aab2aaba46e439 openssl-static-1.0.1e-61.el6_10.1.s390x.rpm SHA-256: 5957c7bdad8d3158b43860b8758302f9fe0d30893e49259f2b6c495293dfadaf The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .