[ELSA-2021-4424] openssl security and bug fix update

Severity Moderate
Affected Packages 4
CVEs 2

- Fixes bugs in s390x AES code.
- Uses the first detected address family if IPv6 is not available
- Reverts the changes in https://github.com/openssl/openssl/pull/13305
as it introduces a regression if server has a DSA key pair, the handshake fails
when the protocol is not explicitly set to TLS 1.2. However, if the patch is reverted,
it has an effect on the 'ssl_reject_handshake' feature in nginx. Although, this feature
will continue to work, TLS 1.3 protocol becomes unavailable/disabled. This is already
known - https://trac.nginx.org/nginx/ticket/2071#comment:1
As per https://github.com/openssl/openssl/issues/16075#issuecomment-879939938, nginx
could early callback instead of servername callback.
- Resolves: rhbz#1978214
- Related: rhbz#1934534

- Cleansup the peer point formats on renegotiation
- Resolves rhbz#1965362

- Fixes FIPS_selftest to work in FIPS mode. Resolves: rhbz#1940085
- Using safe primes for FIPS DH self-test

- Update to version 1.1.1k

- Use AI_ADDRCONFIG only when explicit host name is given
- Allow only curves defined in RFC 8446 in TLS 1.3

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/openssl?distro=oraclelinux-8 oraclelinux openssl < 1.1.1k-4.el8 oraclelinux-8
Affected pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-8 oraclelinux openssl-perl < 1.1.1k-4.el8 oraclelinux-8
Affected pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-8 oraclelinux openssl-libs < 1.1.1k-4.el8 oraclelinux-8
Affected pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-8 oraclelinux openssl-devel < 1.1.1k-4.el8 oraclelinux-8
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date