RHSA-2022:7384HighCVSS 7.5
Red Hat Security Advisory: openssl-container security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2022-3602 — OpenSSL: X.509 Email Address Buffer Overflow CVE-2022-3786 — OpenSSL: X.509 Email Address Variable Length Buffer Overflow
🎯 Affected products9
- Red Hat Enterprise Linux AppStream (v. 9)
- rhel9/openssl@sha256:17d66d6147a8ced8665797de2e909ebd98e4ce7c1db9d42e693e88599c5718a4_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- rhel9/openssl@sha256:3c32d03ba29856387d8f238bd2e17c8dc77a04af509df5664fe6c412ebb15347_ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- rhel9/openssl@sha256:a2af1c9744ae5c382121b446efcd673abb67e9fe017f35b06295628dd69c937c_arm64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- rhel9/openssl@sha256:a33b64e64982f6b9a876ef228abf1b76f553837a46747251cdea4c7576946050_s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
- ubi9/openssl@sha256:17d66d6147a8ced8665797de2e909ebd98e4ce7c1db9d42e693e88599c5718a4_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- ubi9/openssl@sha256:3c32d03ba29856387d8f238bd2e17c8dc77a04af509df5664fe6c412ebb15347_ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)
- ubi9/openssl@sha256:a2af1c9744ae5c382121b446efcd673abb67e9fe017f35b06295628dd69c937c_arm64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- ubi9/openssl@sha256:a33b64e64982f6b9a876ef228abf1b76f553837a46747251cdea4c7576946050_s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2022:7384
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://catalog.redhat.com/software/containers/search
- externalhttps://access.redhat.com/security/vulnerabilities/RHSB-2022-004
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2134869
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2137723
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2139104
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_7384.json