RHSA-2026:67154HighCVSS 7.5

Red Hat Security Advisory: openssl security, bug fix, and enhancement update

Published
September 14, 2026
Last Modified
September 14, 2026

🔗 CVE IDs covered (9)

📋 Description

CVE-2026-14456 — openssl: OpenSSL: Denial of Service via unbounded memory growth in QUIC server CVE-2026-14457 — openssl: RPK server signature algorithm selection can dereference a missing certificate CVE-2026-18798 — openssl: QUIC server may trigger double free when processing INITIAL packet CVE-2026-54874 — openssl: excessive memory use buffering DTLS records for a future epoch CVE-2026-63072 — openssl: heap buffer overflow in CMS key unwrapping CVE-2026-63073 — openssl: untrusted sender DN used as format string in CMP response validation CVE-2026-63074 — openssl: CMP indefinite cache growth of ExtraCerts CVE-2026-63075 — openssl: QUIC ACK-only packet retention can cause memory exhaustion CVE-2026-63076 — openssl: invalid pointer dereference in CMP server via crafted protectionAlg

🎯 Affected products43

  • Red Hat Enterprise Linux AppStream (v. 10)
  • Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-1:3.5.8-1.el10_2.src as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-1:3.5.8-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debuginfo-1:3.5.8-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-debugsource-1:3.5.8-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-devel-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-devel-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-devel-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-devel-1:3.5.8-1.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
  • openssl-libs-1:3.5.8-1.el10_2.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-libs-1:3.5.8-1.el10_2.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • openssl-libs-1:3.5.8-1.el10_2.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 10)
  • +13 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Rate-limit or firewall inbound QUIC (UDP 443) traffic at the network level to reduce exposure. If QUIC server functionality is not required, disable it and use TLS over TCP instead. The upstream fix introduces a default limit of 256 pending connections, configurable via SSL_set_value_uint(3ossl). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (13)