[ELSA-2024-2447] openssl and openssl-fips-provider security update

Severity Low
Affected Packages 5
CVEs 7

openssl
[1:3.0.7-27.0.3]
- Enable openssl-fips-provider dependency [Orabug: 36504822]

[1:3.0.7-27.0.2]
- Temporary disable openssl-fips-provider dependency [Orabug: 36504822]

[1:3.0.7-27.0.1]
- Replace upstream references [Orabug: 34340177]

[1:3.0.7-27]
- Use certified FIPS module instead of freshly built one in Red Hat distribution
Related: RHEL-23474

[1:3.0.7-26]
- Avoid implicit function declaration when building openssl
Related: RHEL-1780
- In FIPS mode, prevent any other operations when rsa_keygen_pairwise_test fails
Resolves: RHEL-17104
- Add a directory for OpenSSL providers configuration
Resolves: RHEL-17193
- Eliminate memory leak in OpenSSL when setting elliptic curves on SSL context
Resolves: RHEL-19515
- POLY1305 MAC implementation corrupts vector registers on PowerPC (CVE-2023-6129)
Resolves: RHEL-21151
- Excessive time spent checking invalid RSA public keys (CVE-2023-6237)
Resolves: RHEL-21654
- SSL ECDHE Kex fails when pkcs11 engine is set in config file
Resolves: RHEL-20249
- Denial of service via null dereference in PKCS#12
Resolves: RHEL-22486
- Use certified FIPS module instead of freshly built one in Red Hat distribution
Resolves: RHEL-23474

openssl-fips-provider
[3.0.7-2.0.1]
- Add bundle with Oracle Linux 9 OpenSSL FIPS Provider module files [Orabug: 36504822]
- Replace upstream references [Orabug: 34340177]

[3.0.7-2]
- Denote conflict with old versions of openssl-libs package
Related: RHEL-23474

[3.0.7-1]
Initial packaging

ID
ELSA-2024-2447
Severity
low
URL
https://linux.oracle.com/errata/ELSA-2024-2447.html
Published
2024-05-03T00:00:00
(4 months ago)
Modified
2024-05-03T00:00:00
(4 months ago)
Rights
Copyright 2024 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/openssl?distro=oraclelinux-9 oraclelinux openssl < 3.0.7-27.0.3.el9 oraclelinux-9
Affected pkg:rpm/oraclelinux/openssl-perl?distro=oraclelinux-9 oraclelinux openssl-perl < 3.0.7-27.0.3.el9 oraclelinux-9
Affected pkg:rpm/oraclelinux/openssl-libs?distro=oraclelinux-9 oraclelinux openssl-libs < 3.0.7-27.0.3.el9 oraclelinux-9
Affected pkg:rpm/oraclelinux/openssl-fips-provider?distro=oraclelinux-9 oraclelinux openssl-fips-provider < 3.0.7-2.0.1.el9 oraclelinux-9
Affected pkg:rpm/oraclelinux/openssl-devel?distro=oraclelinux-9 oraclelinux openssl-devel < 3.0.7-27.0.3.el9 oraclelinux-9
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...