Important: openssl security update
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file (CVE-2025-11187) * openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing (CVE-2025-15467) * openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling (CVE-2025-15468) * openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation (CVE-2025-15469) * openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression (CVE-2025-66199) * openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter (CVE-2025-68160) * openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls (CVE-2025-69418) * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419) * openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing (CVE-2025-69421) * openssl: OpenSSL: Denial of Service via malformed TimeStamp Response (CVE-2025-69420) * openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing (CVE-2026-22795) * openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification (CVE-2026-22796) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library. Security Fix(es): * openssl: OpenSSL: Arbitrary code execution or denial of service through crafted PKCS#12 file (CVE-2025-11187) * openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing (CVE-2025-15467) * openssl: OpenSSL: Denial of Service via NULL pointer dereference in QUIC protocol handling (CVE-2025-15468) * openssl: OpenSSL: Data integrity bypass in `openssl dgst` command due to silent truncation (CVE-2025-15469) * openssl: OpenSSL: Denial of Service due to excessive memory allocation in TLS 1.3 certificate compression (CVE-2025-66199) * openssl: OpenSSL: Denial of Service due to out-of-bounds write in BIO filter (CVE-2025-68160) * openssl: OpenSSL: Information disclosure and data tampering via specific low-level OCB encryption/decryption calls (CVE-2025-69418) * openssl: OpenSSL: Arbitrary code execution due to out-of-bounds write in PKCS#12 processing (CVE-2025-69419) * openssl: OpenSSL: Denial of Service via malformed PKCS#12 file processing (CVE-2025-69421) * openssl: OpenSSL: Denial of Service via malformed TimeStamp Response (CVE-2025-69420) * openssl: OpenSSL: Denial of Service due to type confusion in PKCS#12 file processing (CVE-2026-22795) * openssl: OpenSSL: Denial of Service via type confusion in PKCS#7 signature verification (CVE-2026-22796) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:1472
- https://access.redhat.com/security/cve/CVE-2025-11187
- https://access.redhat.com/security/cve/CVE-2025-15467
- https://access.redhat.com/security/cve/CVE-2025-15468
- https://access.redhat.com/security/cve/CVE-2025-15469
- https://access.redhat.com/security/cve/CVE-2025-66199
- https://access.redhat.com/security/cve/CVE-2025-68160
- https://access.redhat.com/security/cve/CVE-2025-69418
- https://access.redhat.com/security/cve/CVE-2025-69419
- https://access.redhat.com/security/cve/CVE-2025-69420
- https://access.redhat.com/security/cve/CVE-2025-69421
- https://access.redhat.com/security/cve/CVE-2026-22795
- https://access.redhat.com/security/cve/CVE-2026-22796
- https://bugzilla.redhat.com/2430375
- https://bugzilla.redhat.com/2430376
- https://bugzilla.redhat.com/2430377
- https://bugzilla.redhat.com/2430378
- https://bugzilla.redhat.com/2430379
- https://bugzilla.redhat.com/2430380
- https://bugzilla.redhat.com/2430381
- https://bugzilla.redhat.com/2430386
- https://bugzilla.redhat.com/2430387
- https://bugzilla.redhat.com/2430388
- https://bugzilla.redhat.com/2430389
- https://bugzilla.redhat.com/2430390
- https://errata.almalinux.org/10/ALSA-2026-1472.html