RHSA-2026:71542HighCVSS 9.1

Red Hat Security Advisory: openssl security update

Published
September 24, 2026
Last Modified
September 24, 2026

🔗 CVE IDs covered (7)

📋 Description

CVE-2025-69418 — openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls CVE-2026-28390 — openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing CVE-2026-31790 — openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key CVE-2026-34182 — openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages CVE-2026-34183 — openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler CVE-2026-45445 — openssl: AES-OCB IV Ignored on EVP_Cipher() Path CVE-2026-45447 — openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()

🎯 Affected products43

  • Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-1:3.2.2-16.el10_0.7.src as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-1:3.2.2-16.el10_0.7.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debuginfo-1:3.2.2-16.el10_0.7.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-debugsource-1:3.2.2-16.el10_0.7.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-devel-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-devel-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-devel-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-devel-1:3.2.2-16.el10_0.7.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v. 10.0)
  • openssl-libs-1:3.2.2-16.el10_0.7.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-libs-1:3.2.2-16.el10_0.7.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • openssl-libs-1:3.2.2-16.el10_0.7.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v. 10.0)
  • +13 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Applications that process Cryptographic Message Syntax (CMS) EnvelopedData messages should be configured to only accept input from trusted sources. Restricting network access to services that process untrusted CMS data can also reduce exposure to this Denial of Service vulnerability. Workaround: Systems configured to operate in FIPS mode are not affected by this vulnerability. To mitigate this issue, ensure that OpenSSL is operating in FIPS mode by enabling the system-wide FIPS policy. This may have broader implications for cryptographic operations on the system and should be evaluated for compatibility with existing applications. A system reboot may be required for the changes to take effect. Workaround: To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack.

🔗 References (10)