Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (13)
📋 Description
CVE-2026-35189 — openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing CVE-2026-35191 — openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting CVE-2026-42772 — openssl: openssl: Denial of Service via inefficient QUIC stream reassembly CVE-2026-54872 — openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations CVE-2026-54873 — openssl: openssl: Denial of Service via excessive QUIC packet buffer retention CVE-2026-54875 — openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V CVE-2026-72897 — openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch CVE-2026-75804 — openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control CVE-2026-75805 — openssl: openssl: Denial of Service via crafted CMP certificate revocation response CVE-2026-75806 — openssl: OpenSSL: Denial of Service via undersized DTLS record CVE-2026-77696 — openssl: OpenSSL: Private key recovery via SM2 timing side-channel CVE-2026-84782 — openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission CVE-2026-84784 — openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog
🎯 Affected products8
- Red Hat Hardened Images
- openssl3-0:3.5.9-0.1.hum1@src as a component of Red Hat Hardened Images
- openssl3-devel-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- openssl3-devel-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- openssl3-devel-engine-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- openssl3-devel-engine-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
- openssl3-libs-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images
- openssl3-libs-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Do not revoke certificates over CMP by supplying a PKCS#10 CSR (`openssl cmp -cmd rr -csr ...` or `OSSL_CMP_CTX_set1_p10CSR()`). Identify the certificate by certificate or by issuer name and serial number instead. Restrict CMP clients to trusted CMP servers and protect CMP message-protection credentials. If CMP certificate revocation is unused, avoid enabling CMP client revocation workflows.
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:74166
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-75806
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-54875
- externalhttps://access.redhat.com/security/cve/CVE-2026-42772
- externalhttps://access.redhat.com/security/cve/CVE-2026-35189
- externalhttps://access.redhat.com/security/cve/CVE-2026-35191
- externalhttps://access.redhat.com/security/cve/CVE-2026-77696
- externalhttps://access.redhat.com/security/cve/CVE-2026-84784
- externalhttps://access.redhat.com/security/cve/CVE-2026-75804
- externalhttps://access.redhat.com/security/cve/CVE-2026-54873
- externalhttps://access.redhat.com/security/cve/CVE-2026-54872
- externalhttps://access.redhat.com/security/cve/CVE-2026-75805
- externalhttps://access.redhat.com/security/cve/CVE-2026-72897
- externalhttps://access.redhat.com/security/cve/CVE-2026-84782
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74166.json