FlawAtlas
Search the atlas
SUSE-SU-2026:21544-1 Not scored

Security update for openssl-3-x86_64-v3-livepatches

This update for openssl-3-x86_64-v3-livepatches fixes the following issues: Changes in openssl-3-x86_64-v3-livepatches: - Add package for libopenssl3-x86-64-v3-3.5.0 (bsc#1259271). Fixed: - CVE-2025-11187: Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Fixed Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2025-9230: Fixed Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) (bsc#1250410).

Exploit probability Not scored
Published May 5, 2026
Required by Not available
Last source change May 12, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:21544-1

This update for openssl-3-x86_64-v3-livepatches fixes the following issues: Changes in openssl-3-x86_64-v3-livepatches: - Add package for libopenssl3-x86-64-v3-3.5.0 (bsc#1259271). Fixed: - CVE-2025-11187: Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Fixed Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: Fixed NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2025-9230: Fixed Out-of-bounds read & write in RFC 3211 KEK Unwrap (CVE-2025-9230) (bsc#1250410).

View original source

05 / REFERENCES

Further evidence