RHSA-2024:9333: Low: openssl and openssl-fips-provider security update
Low: openssl and openssl-fips-provider security update
Other sources
OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols, as well as a full-strength general-purpose cryptography library.Security Fix(es): openssl: Unbounded memory growth with session handling in TLSv1.3 (CVE-2024-2511) openssl: Excessive time spent checking DSA keys and parameters (CVE-2024-4603) openssl: Use After Free with SSLfreebuffers (CVE-2024-4741) openssl: SSLselectnextproto buffer overread (CVE-2024-5535) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 9.5 Release Notes linked from the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2024:9333?
The severity of RHSA-2024:9333 is classified as Low.
How do I fix RHSA-2024:9333?
To fix RHSA-2024:9333, update the affected packages to the version 3.2.2-6.el9_5 for openssl and 3.0.7-6.el9_5 for openssl-fips-provider.
Which systems are impacted by RHSA-2024:9333?
RHSA-2024:9333 impacts Red Hat Enterprise Linux for Power, x86_64, IBM z Systems, and ARM 64 architectures.
What are the main issues addressed in RHSA-2024:9333?
RHSA-2024:9333 addresses security vulnerabilities related to OpenSSL that could lead to unbounded memory consumption.
Is RHSA-2024:9333 related to OpenSSL?
Yes, RHSA-2024:9333 specifically addresses vulnerabilities in the OpenSSL toolkit and its FIPS provider.