Security update for openssl-3-livepatches
This update for openssl-3-livepatches fixes the following issues - CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266389, bsc#1266357).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for openssl-3-livepatches fixes the following issues - CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266389, bsc#1266357).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1256876
- https://bugzilla.suse.com/1256878
- https://bugzilla.suse.com/1256880
- https://bugzilla.suse.com/1266357
- https://bugzilla.suse.com/1266389
- https://www.suse.com/security/cve/CVE-2025-11187
- https://www.suse.com/security/cve/CVE-2025-15467
- https://www.suse.com/security/cve/CVE-2025-15468
- https://www.suse.com/security/cve/CVE-2026-45447
- https://www.suse.com/support/update/announcement/2026/suse-su-20262662-1/