RHSA-2026:36217: Important: compat-openssl10 security update
Important: compat-openssl10 security update
Other sources
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries and is provided for compatibility with previous releases and software that does not support compilation with OpenSSL-1.1.Security Fix(es): openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) openssl: Heap Use-After-Free in OpenSSL PKCS7verify() (CVE-2026-45447) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/compat-openssl10to a version that resolves this vulnerability.Fixed in 1.0.2o-4.el8_8.1 - Upgrade
Upgrade
redhat/compat-openssl10-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.2o-4.el8_8.1 - Upgrade
Upgrade
redhat/compat-openssl10-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.2o-4.el8_8.1 - Compensating control
Apply the Red Hat compatibility OpenSSL security update for the “compat-openssl10” package as described in the advisory referenced by https://access.redhat.com/articles/11258, which includes the changes for the OpenSSL PKCS7_verify() heap use-after-free (CVE-2026-45447) and the CMS EnvelopedData NULL pointer dereference denial of service (CVE-2026-28390).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:36217?
The severity of RHSA-2026:36217 is classified as high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:36217?
RHSA-2026:36217 addresses vulnerabilities related to Use After Free and Null Pointer Dereference.
How do I fix RHSA-2026:36217?
To fix RHSA-2026:36217, update the compat-openssl10 package to the latest version provided by Red Hat.
What software is affected by RHSA-2026:36217?
RHSA-2026:36217 affects the compat-openssl10 packages and their debuginfo and debugsource counterparts.
When was RHSA-2026:36217 published?
RHSA-2026:36217 was published on July 7, 2026.