RHSA-2024:2447: Low: openssl and openssl-fips-provider security update
Low: openssl and openssl-fips-provider security update
Other sources
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries (CVE-2023-2975) openssl: Excessive time spent checking DH keys and parameters (CVE-2023-3446) OpenSSL: Excessive time spent checking DH q parameter value (CVE-2023-3817) openssl: Generating excessively long X9.42 DH keys or checking excessively long X9.42 DH keys or parameters may be very slow (CVE-2023-5678) openssl: POLY1305 MAC implementation corrupts vector registers on PowerPC (CVE-2023-6129) openssl: Excessive time spent checking invalid RSA public keys (CVE-2023-6237) openssl: denial of service via null dereference (CVE-2024-0727) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.4 Release Notes linked from the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:2447?
The vulnerability RHSA-2024:2447 is classified as low severity.
How do I fix RHSA-2024:2447?
You can remediate RHSA-2024:2447 by updating your OpenSSL to version 3.0.7-27.el9.
Which software is affected by RHSA-2024:2447?
RHSA-2024:2447 affects multiple versions of Red Hat Enterprise Linux, including Power, IBM z Systems, x86_64, and ARM 64.
What components are updated in RHSA-2024:2447?
The security update in RHSA-2024:2447 includes the openssl and openssl-fips-provider components.
Is RHSA-2024:2447 related to SSL or TLS?
Yes, RHSA-2024:2447 is related to OpenSSL, which implements the SSL and TLS protocols.