FlawAtlas
Search the atlas
SUSE-SU-2026:2662-1 Not scored

Security update for openssl-3-livepatches

This update for openssl-3-livepatches fixes the following issues - CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266389, bsc#1266357).

Exploit probability Not scored
Published June 26, 2026
Required by Not available
Last source change June 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 15 SP7 openssl-3-livepatches

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:2662-1

This update for openssl-3-livepatches fixes the following issues - CVE-2025-11187: Improper validation of PBMAC1 parameters in PKCS#12 MAC verification (bsc#1256878). - CVE-2025-15467: Stack buffer overflow in CMS AuthEnvelopedData parsing (bsc#1256876). - CVE-2025-15468: NULL dereference in SSL_CIPHER_find() function on unknown cipher ID (bsc#1256880). - CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266389, bsc#1266357).

View original source

05 / REFERENCES

Further evidence