Red Hat Security Advisory: openssl security update
🔗 CVE IDs covered (15)
📋 Description
CVE-2026-7383 — openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing CVE-2026-9076 — openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption CVE-2026-34180 — openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. CVE-2026-34181 — openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CVE-2026-42764 — openssl: NULL pointer dereference in QUIC server initial packet handling CVE-2026-42766 — openssl: Possible NULL Dereference in Password-Based CMS Decryption CVE-2026-42767 — openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption CVE-2026-42768 — openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() CVE-2026-42769 — openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate CVE-2026-42770 — openssl: FFC-DH Peer Validation Uses Attacker-Supplied q CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path CVE-2026-45446 — openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:25237
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481879
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481880
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481881
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481882
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481884
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481885
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481887
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481890
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481892
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481893
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481894
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481896
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481897
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2481898
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25237.json