{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "An update for openssl is now available for Red Hat Enterprise Linux 9.\n\nRed Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.",
        "title": "Topic"
      },
      {
        "category": "general",
        "text": "OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.\n\nSecurity Fix(es):\n\n* openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing (CVE-2026-7383)\n\n* openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption (CVE-2026-9076)\n\n* openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure. (CVE-2026-34180)\n\n* openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys (CVE-2026-34181)\n\n* openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages (CVE-2026-34182)\n\n* openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (CVE-2026-34183)\n\n* openssl: NULL pointer dereference in QUIC server initial packet handling (CVE-2026-42764)\n\n* openssl: Possible NULL Dereference in Password-Based CMS Decryption (CVE-2026-42766)\n\n* openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption (CVE-2026-42767)\n\n* openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (CVE-2026-42768)\n\n* openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (CVE-2026-42769)\n\n* openssl: FFC-DH Peer Validation Uses Attacker-Supplied q (CVE-2026-42770)\n\n* openssl: AES-OCB IV Ignored on EVP_Cipher() Path (CVE-2026-45445)\n\n* openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (CVE-2026-45446)\n\n* openssl: Heap Use-After-Free in OpenSSL PKCS7_verify() (CVE-2026-45447)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.",
        "title": "Details"
      },
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://access.redhat.com/errata/RHSA-2026:25239",
        "url": "https://access.redhat.com/errata/RHSA-2026:25239"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/updates/classification/#important",
        "url": "https://access.redhat.com/security/updates/classification/#important"
      },
      {
        "category": "external",
        "summary": "2481879",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
      },
      {
        "category": "external",
        "summary": "2481880",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
      },
      {
        "category": "external",
        "summary": "2481881",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
      },
      {
        "category": "external",
        "summary": "2481882",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
      },
      {
        "category": "external",
        "summary": "2481884",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
      },
      {
        "category": "external",
        "summary": "2481885",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
      },
      {
        "category": "external",
        "summary": "2481887",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
      },
      {
        "category": "external",
        "summary": "2481890",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
      },
      {
        "category": "external",
        "summary": "2481891",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
      },
      {
        "category": "external",
        "summary": "2481892",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
      },
      {
        "category": "external",
        "summary": "2481893",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
      },
      {
        "category": "external",
        "summary": "2481894",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
      },
      {
        "category": "external",
        "summary": "2481896",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
      },
      {
        "category": "external",
        "summary": "2481897",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
      },
      {
        "category": "external",
        "summary": "2481898",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_25239.json"
      }
    ],
    "title": "Red Hat Security Advisory: openssl security update",
    "tracking": {
      "current_release_date": "2026-09-11T09:25:39+00:00",
      "generator": {
        "date": "2026-09-11T09:25:39+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.18"
        }
      },
      "id": "RHSA-2026:25239",
      "initial_release_date": "2026-06-11T13:24:31+00:00",
      "revision_history": [
        {
          "date": "2026-06-11T13:24:31+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-06-11T13:24:31+00:00",
          "number": "2",
          "summary": "Last updated version"
        },
        {
          "date": "2026-09-11T09:25:39+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux AppStream (v. 9)",
                "product": {
                  "name": "Red Hat Enterprise Linux AppStream (v. 9)",
                  "product_id": "AppStream-9.8.0.Z.MAIN.EUS",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:enterprise_linux:9::appstream"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat Enterprise Linux BaseOS (v. 9)",
                "product": {
                  "name": "Red Hat Enterprise Linux BaseOS (v. 9)",
                  "product_id": "BaseOS-9.8.0.Z.MAIN.EUS",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:redhat:enterprise_linux:9::baseos"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Enterprise Linux"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:3.5.5-4.el9_8.src",
                "product": {
                  "name": "openssl-1:3.5.5-4.el9_8.src",
                  "product_id": "openssl-1:3.5.5-4.el9_8.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.5-4.el9_8?arch=src&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-libs-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-libs-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debugsource@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debuginfo@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs-debuginfo@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-devel-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-devel-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:3.5.5-4.el9_8.aarch64",
                "product": {
                  "name": "openssl-perl-1:3.5.5-4.el9_8.aarch64",
                  "product_id": "openssl-perl-1:3.5.5-4.el9_8.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@3.5.5-4.el9_8?arch=aarch64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-libs-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-libs-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debugsource@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debuginfo@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs-debuginfo@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-devel-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-devel-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:3.5.5-4.el9_8.ppc64le",
                "product": {
                  "name": "openssl-perl-1:3.5.5-4.el9_8.ppc64le",
                  "product_id": "openssl-perl-1:3.5.5-4.el9_8.ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@3.5.5-4.el9_8?arch=ppc64le&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-libs-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-libs-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debugsource@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debuginfo@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs-debuginfo@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-devel-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-devel-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:3.5.5-4.el9_8.x86_64",
                "product": {
                  "name": "openssl-perl-1:3.5.5-4.el9_8.x86_64",
                  "product_id": "openssl-perl-1:3.5.5-4.el9_8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@3.5.5-4.el9_8?arch=x86_64&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-libs-1:3.5.5-4.el9_8.i686",
                "product": {
                  "name": "openssl-libs-1:3.5.5-4.el9_8.i686",
                  "product_id": "openssl-libs-1:3.5.5-4.el9_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.5-4.el9_8?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debugsource-1:3.5.5-4.el9_8.i686",
                "product": {
                  "name": "openssl-debugsource-1:3.5.5-4.el9_8.i686",
                  "product_id": "openssl-debugsource-1:3.5.5-4.el9_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debugsource@3.5.5-4.el9_8?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debuginfo-1:3.5.5-4.el9_8.i686",
                "product": {
                  "name": "openssl-debuginfo-1:3.5.5-4.el9_8.i686",
                  "product_id": "openssl-debuginfo-1:3.5.5-4.el9_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debuginfo@3.5.5-4.el9_8?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
                "product": {
                  "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
                  "product_id": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs-debuginfo@3.5.5-4.el9_8?arch=i686&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:3.5.5-4.el9_8.i686",
                "product": {
                  "name": "openssl-devel-1:3.5.5-4.el9_8.i686",
                  "product_id": "openssl-devel-1:3.5.5-4.el9_8.i686",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.5-4.el9_8?arch=i686&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "i686"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-libs-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-libs-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debugsource-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-debugsource-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-debugsource-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debugsource@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-debuginfo@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs-debuginfo@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-devel-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-devel-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-1:3.5.5-4.el9_8.s390x",
                "product": {
                  "name": "openssl-perl-1:3.5.5-4.el9_8.s390x",
                  "product_id": "openssl-perl-1:3.5.5-4.el9_8.s390x",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@3.5.5-4.el9_8?arch=s390x&epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "s390x"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-devel-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-devel-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-devel-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-devel-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-devel-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-perl-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-perl-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-perl-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 9)",
          "product_id": "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-perl-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "AppStream-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:3.5.5-4.el9_8.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src"
        },
        "product_reference": "openssl-1:3.5.5-4.el9_8.src",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-libs-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-libs-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-libs-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-libs-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-libs-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)",
          "product_id": "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        },
        "product_reference": "openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
        "relates_to_product_reference": "BaseOS-9.8.0.Z.MAIN.EUS"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-7383",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "discovery_date": "2026-05-27T13:08:15.013000+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481879"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A signed integer overflow vulnerability exists when sizing the destination buffer for Unicode output. This can lead to a heap buffer overflow, which may result in a crash or potentially allow an attacker to execute arbitrary code. Exploitation requires an application to directly call specific functions with a large amount of attacker-controlled input.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Low impact. This flaw in OpenSSL's ASN1_mbstring_ncopy() function, leading to a heap buffer overflow, is difficult to exploit in typical Red Hat environments. Exploitation requires an application to directly call the vulnerable function with an extremely large, attacker-controlled input (over half a gigabyte), a scenario not present in standard OpenSSL certificate or network protocol handling.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-7383"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481879",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481879"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-7383",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-7383"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 5.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: OpenSSL: Heap buffer overflow due to signed integer overflow in Unicode output sizing"
    },
    {
      "cve": "CVE-2026-9076",
      "cwe": {
        "id": "CWE-131",
        "name": "Incorrect Calculation of Buffer Size"
      },
      "discovery_date": "2026-05-27T13:10:14.368000+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481880"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. When processing attacker-supplied Cryptographic Message Syntax (CMS) data using password-based decryption, an attacker can choose a stream-mode Key Encryption Key (KEK) cipher. This can trigger a heap out-of-bounds read, potentially causing an application crash and leading to a Denial of Service (DoS). This vulnerability does not require password knowledge and can be exploited before authentication.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is a Low impact denial of service due to a heap out-of-bounds read in `kek_unwrap_key()` when processing attacker-supplied CMS data with an attacker-chosen stream-mode KEK cipher. This flaw requires specific memory conditions (input buffer ending at a page boundary with an unmapped following page) to trigger a crash, which is uncommon in typical Red Hat environments. No information disclosure is possible, and FIPS modules are not affected.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-9076"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481880",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481880"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-9076",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-9076"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: OpenSSL: Denial of Service due to heap out-of-bounds read in CMS password-based decryption"
    },
    {
      "cve": "CVE-2026-34180",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "discovery_date": "2026-05-27T13:10:51.985000+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481881"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. An integer truncation vulnerability in the ASN.1 decoder can occur when processing a crafted DER-encoded ASN.1 structure with a primitive element exceeding 2 gigabytes. A remote attacker could exploit this to cause a heap buffer over-read. This may lead to an application crash, resulting in a Denial of Service (DoS), or potentially disclose sensitive information by loading memory contents beyond the input buffer. This issue primarily affects 64-bit Unix and Unix-like platforms.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure.",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This Low impact vulnerability in OpenSSL's ASN.1 decoder affects 64-bit Unix-like platforms, where processing a crafted DER-encoded ASN.1 structure exceeding 2 gigabytes can lead to a heap buffer over-read. This may result in application crashes (Denial of Service) or unintended memory exposure. Red Hat products are only affected if they process untrusted, excessively large ASN.1 input using OpenSSL's d2i_* decoding functions.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-34180"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481881",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481881"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-34180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34180"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: OpenSSL: Heap buffer over-read in ASN.1 decoding can lead to denial of service or information disclosure."
    },
    {
      "cve": "CVE-2026-34181",
      "cwe": {
        "id": "CWE-347",
        "name": "Improper Verification of Cryptographic Signature"
      },
      "discovery_date": "2026-05-02T00:00:00+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481882"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to forge PKCS#12 (Public-Key Cryptography Standards #12) files that use Password-Based Message Authentication Code 1 (PBMAC1) with short HMAC (Hash-based Message Authentication Code) keys. This can lead to a service accepting attacker-controlled certificates and private keys with a 1 in 256 probability, potentially enabling impersonation.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Low: This flaw allows an attacker to forge PKCS#12 files with a 1 in 256 probability, leading to the acceptance of attacker-controlled certificates and private keys by services configured to use PBMAC1 authentication. Red Hat products utilizing OpenSSL versions 3.0, 1.1.1, or 1.0.2 are not affected, as these versions do not support PBMAC1 in PKCS#12.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-34181"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481882",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481882"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-34181",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34181"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-34181",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34181"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "To mitigate this issue, enforce strict validation on all uploaded PKCS#12 files to reject those containing abnormally short security keys. Additionally, enabling FIPS mode on your system can help protect your environment, as the vulnerable OpenSSL code operates entirely outside the approved FIPS cryptographic boundary.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys"
    },
    {
      "cve": "CVE-2026-34182",
      "cwe": {
        "id": "CWE-130",
        "name": "Improper Handling of Length Parameter Inconsistency"
      },
      "discovery_date": "2026-05-27T13:59:43+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481884"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing. An on-path attacker can exploit insufficient input validation on cipher and tag length fields by sending specially crafted CMS messages. This can lead to the forging of messages or bypassing integrity validation. Consequently, an attacker may achieve key-equivalent functionality for a given CMS recipient.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "Moderate: This flaw in OpenSSL's Cryptographic Message Services (CMS) AuthEnvelopedData processing could allow an on-path attacker to forge messages or bypass integrity validation. This is due to insufficient input validation on cipher and tag length fields, potentially leading to key-equivalent functionality or integrity bypass in applications utilizing affected OpenSSL versions for CMS AuthEnvelopedData.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-34182"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481884",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481884"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-34182",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34182"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-34182",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34182"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Systems configured to operate in FIPS mode are not affected by this vulnerability. To mitigate this issue, ensure that OpenSSL is operating in FIPS mode by enabling the system-wide FIPS policy. This may have broader implications for cryptographic operations on the system and should be evaluated for compatibility with existing applications. A system reboot may be required for the changes to take effect.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: CMS AuthEnvelopedData Processing May Accept Forged Messages"
    },
    {
      "cve": "CVE-2026-34183",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-05-27T14:04:59+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481885"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL's QUIC PATH_CHALLENGE handler. A remote attacker can exploit this vulnerability by flooding a QUIC client or server with specially crafted PATH_CHALLENGE frames. This leads to unbounded memory allocation within the local QUIC stack, as the system continuously allocates PATH_RESPONSE frames without them being acknowledged. The primary consequence is a Denial of Service (DoS), causing the affected application to terminate abnormally due to memory exhaustion.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "A Moderate severity flaw exists in the QUIC PATH_CHALLENGE handler, allowing a remote attacker to exhaust heap memory of a QUIC client or server. By flooding the local QUIC stack with PATH_CHALLENGE frames, a malicious peer can trigger unbounded memory allocation, leading to a denial of service for applications utilizing the vulnerable QUIC implementation.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-34183"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481885",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481885"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-34183",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-34183"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34183"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "To mitigate this vulnerability, apply UDP rate limiting at your network edge to throttle malicious traffic. If QUIC is not strictly required, disable the listener entirely and configure your application to use standard TLS over TCP. Additionally, enforce strict process memory limits using cgroups to prevent host-wide memory exhaustion during an attack.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler"
    },
    {
      "cve": "CVE-2026-42764",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "discovery_date": "2026-05-27T14:08:07+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481887"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the OpenSSL QUIC (Quick UDP Internet Connections) server. A remote attacker could send a specially crafted QUIC initial packet with an invalid token. If the server's address validation is explicitly disabled, this could lead to a NULL pointer dereference, causing the server process to terminate abnormally and resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: NULL pointer dereference in QUIC server initial packet handling",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is a Moderate severity issue. A NULL pointer dereference can occur in the OpenSSL QUIC server when processing initial packets with invalid tokens, leading to a denial of service. This vulnerability is only exploitable if the client address validation is explicitly disabled using the `SSL_LISTENER_FLAG_NO_VALIDATE` flag, which is not the default configuration for OpenSSL QUIC servers.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42764"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481887",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481887"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42764",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42764"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42764",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42764"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "To mitigate this issue, ensure that the OpenSSL QUIC server has client address validation enabled. This is the default configuration. If the `SSL_LISTENER_FLAG_NO_VALIDATE` flag is being used with the `SSL_new_listener()` call, it should be removed to prevent the vulnerability from being exploitable.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: NULL pointer dereference in QUIC server initial packet handling"
    },
    {
      "cve": "CVE-2026-42766",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481890"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote attacker could exploit a NULL pointer dereference vulnerability in the Cryptographic Message Syntax (CMS) decryption process by providing a specially crafted password-encrypted CMS message. This occurs because the keyDerivationAlgorithm field, which is optional, is dereferenced without proper validation. Successful exploitation leads to an application crash, resulting in a Denial of Service.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: Possible NULL Dereference in Password-Based CMS Decryption",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This issue is rated as Low impact. A NULL pointer dereference in OpenSSL's CMS decryption can be triggered by a specially crafted password-encrypted CMS message, leading to an Red Hat application crash and Denial of Service. This affects applications that perform password-based CMS decryption.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42766"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481890",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481890"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42766",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42766"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: Possible NULL Dereference in Password-Based CMS Decryption"
    },
    {
      "cve": "CVE-2026-42767",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481891"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. An attacker controlling a Certificate Management Protocol (CMP) server, or acting as a man-in-the-middle, could craft a malicious CMP response. This response, containing a Certificate Request Message Format (CRMF) CertRepMessage with a specific malformed EncryptedValue structure, would trigger a NULL pointer dereference in the OpenSSL CMP client. This vulnerability leads to a crash of the application, resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is a Low severity issue. A null pointer dereference flaw in the OpenSSL Certificate Management Protocol (CMP) client could be triggered by an attacker-controlled CMP server. This could lead to a denial of service in applications that process untrusted CMP/CRMF messages.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42767"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481891",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481891"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42767",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42767"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42767"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "To mitigate this issue, ensure that OpenSSL CMP client applications only communicate with trusted Certificate Management Protocol (CMP) servers. If CMP client functionality is not required, consider disabling or restricting its use to reduce exposure.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: NULL Pointer Dereference in CRMF EncryptedValue Decryption"
    },
    {
      "cve": "CVE-2026-42768",
      "cwe": {
        "id": "CWE-205",
        "name": "Observable Behavioral Discrepancy"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481892"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions. This vulnerability, a Bleichenbacher-style oracle, could allow a remote attacker to decrypt or sign messages using the victim's private RSA key. Exploitation requires the attacker to provide specially crafted CMS or S/MIME messages and observe the application's error codes or decryption output. While the attack is technically possible, the specific conditions required make it unlikely to be exploited in typical deployments.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This Low severity vulnerability in OpenSSL's CMS_decrypt() and PKCS7_decrypt() functions exposes a Bleichenbacher-style oracle. Exploitation requires an attacker to control input CMS/S/MIME messages and observe decryption errors or output, a scenario deemed unlikely in most Red Hat product deployments. The attack could allow decryption or signing of messages with a victim's private RSA key.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42768"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481892",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481892"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42768",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42768"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42768"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "To mitigate this vulnerability, applications utilizing CMS_decrypt() or PKCS7_decrypt() should ensure a recipient certificate is always provided to identify the specific RecipientInfo for decryption. This practice helps prevent the Bleichenbacher-style oracle attack by ensuring proper key identification.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 6.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()"
    },
    {
      "cve": "CVE-2026-42769",
      "cwe": {
        "id": "CWE-295",
        "name": "Improper Certificate Validation"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481893"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in the Certificate Management Protocol (CMP) implementation within OpenSSL. An attacker with existing Registration Authority (RA) level credentials could exploit an error in the certificate verification process during a Root Certificate Authority (CA) key update. This vulnerability allows the attacker to replace the root CA certificate for CMP clients with a fraudulent one. The primary consequence is an escalation of privileges, enabling the attacker to gain control equivalent to the root CA.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This issue has a Low impact as it requires an attacker to already possess valid Registration Authority (RA) level credentials to exploit. A flaw in the Certificate Management Protocol (CMP) root CA key update process could allow an RA to substitute the root CA certificate for CMP clients with an arbitrary certificate, potentially leading to a trust-anchor substitution. FIPS modules are not affected.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42769"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481893",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481893"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42769",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42769"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42769",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42769"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "HIGH",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate"
    },
    {
      "cve": "CVE-2026-42770",
      "cwe": {
        "id": "CWE-354",
        "name": "Improper Validation of Integrity Check Value"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481894"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A malicious peer can exploit this vulnerability by presenting a specially crafted DHX (X9.42) peer key. Due to improper validation of the peer key's subgroup membership, an attacker can recover the victim's private key after a small number of key exchange attempts. This information disclosure can lead to unauthorized access or further compromise of affected systems.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: FFC-DH Peer Validation Uses Attacker-Supplied q",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This Low severity flaw in OpenSSL affects systems configured to use DHX (X9.42) peer keys for key derivation, allowing a malicious peer to potentially recover a victim's private key. The attack requires specific conditions, such as long-lived RA/CA DHX keys in CMP deployments or bespoke applications utilizing X9.42 DHX static keys with interactive protocols, limiting its broader impact.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42770"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481894",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481894"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42770",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42770"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: FFC-DH Peer Validation Uses Attacker-Supplied q"
    },
    {
      "cve": "CVE-2026-45445",
      "cwe": {
        "id": "CWE-1204",
        "name": "Generation of Weak Initialization Vector (IV)"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481896"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. Applications that use the AES-OCB encryption method with a specific one-shot interface (EVP_Cipher()) will have their provided Initialization Vector (IV) silently discarded. This leads to the same internal cryptographic value being used repeatedly, which compromises the confidentiality of encrypted data. Additionally, this issue allows for the universal forgery of authentication tags, undermining the integrity of communications.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: AES-OCB IV Ignored on EVP_Cipher() Path",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This is a Moderate severity flaw where applications utilizing the AES-OCB cipher through OpenSSL's EVP_Cipher() one-shot interface may silently discard the provided initialization vector (IV). This leads to nonce reuse, compromising confidentiality and enabling universal forgery of authentication tags. Red Hat products are primarily affected if they include or rely on third-party applications that specifically employ this less common and discouraged API usage with AES-OCB, as standard OpenSSL SSL/TLS implementations and applications using the recommended streaming AEAD API are not impacted.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-45445"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481896",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481896"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-45445",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45445"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-45445",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45445"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 9.1,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: AES-OCB IV Ignored on EVP_Cipher() Path"
    },
    {
      "cve": "CVE-2026-45446",
      "cwe": {
        "id": "CWE-347",
        "name": "Improper Verification of Cryptographic Signature"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481897"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. The implementations of AES-SIV (Advanced Encryption Standard - SIV) and AES-GCM-SIV (Advanced Encryption Standard - Galois/Counter Mode - SIV) incorrectly process authentication tags for empty messages. This vulnerability allows a remote attacker to forge empty messages with arbitrary Additional Authenticated Data (AAD) in applications that utilize these specific cipher modes within custom protocols and do not properly handle zero-length ciphertexts. This could lead to unauthorized data manipulation.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This flaw is rated as Low impact. It affects applications that utilize OpenSSL's AES-SIV or AES-GCM-SIV modes within custom protocols and specifically mishandle empty ciphertexts. Standard OpenSSL protocols, such as TLS, are not affected. Successful exploitation requires an application to use the EVP interface and to skip ciphertext updates when processing zero-length ciphertexts, representing an uncommon and non-default configuration.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-45446"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481897",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481897"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-45446",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45446"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-45446",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45446"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "The vulnerability arises from specific application implementations using OpenSSL's AES-SIV or AES-GCM-SIV modes with custom protocols and an atypical handling of empty ciphertexts. As this scenario is not a default or commonly deployed configuration in Red Hat products, and no direct configuration or operational control exists to mitigate this specific flaw without patching, the following applies:\n\nMitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes"
    },
    {
      "cve": "CVE-2026-45447",
      "cwe": {
        "id": "CWE-825",
        "name": "Expired Pointer Dereference"
      },
      "discovery_date": "2026-05-27T14:17:46+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2481898"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. When processing a specially crafted PKCS#7 or S/MIME (Secure/Multipurpose Internet Mail Extensions) signed message, a heap use-after-free vulnerability in the PKCS7_verify() function can be triggered. This occurs if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, leading to incorrect memory deallocation. A remote attacker could exploit this to cause application crashes, memory corruption, or potentially achieve remote code execution.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This High severity heap use-after-free flaw in OpenSSL's PKCS7_verify() function can be triggered by processing a specially crafted PKCS#7 or S/MIME signed message. This could lead to application crashes, memory corruption, or potentially remote code execution, impacting services that handle such messages. The vulnerability specifically affects applications utilizing OpenSSL PKCS#7 APIs, while those using CMS APIs are not impacted.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
          "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
          "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-45447"
        },
        {
          "category": "external",
          "summary": "RHBZ#2481898",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2481898"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-45447",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-45447"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-45447"
        }
      ],
      "release_date": "2026-06-09T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-06-11T13:24:31+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:25239"
        },
        {
          "category": "workaround",
          "details": "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.",
          "product_ids": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-devel-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.aarch64",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.ppc64le",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.s390x",
            "AppStream-9.8.0.Z.MAIN.EUS:openssl-perl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.src",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debuginfo-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-debugsource-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-1:3.5.5-4.el9_8.x86_64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.aarch64",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.i686",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.ppc64le",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.s390x",
            "BaseOS-9.8.0.Z.MAIN.EUS:openssl-libs-debuginfo-1:3.5.5-4.el9_8.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "openssl: Heap Use-After-Free in OpenSSL PKCS7_verify()"
    }
  ]
}