RHSA-2026:44480: Moderate: compat-openssl10 security update
Moderate: compat-openssl10 security update
Other sources
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries and is provided for compatibility with previous releases and software that does not support compilation with OpenSSL-1.1.Security Fix(es): openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
compat-openssl10 security update (OpenSSL toolkit libraries for compatibility)to a version that resolves this vulnerability.Patch CVE-2026-28390
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:44480?
The severity of RHSA-2026:44480 is classified as medium.
How do I fix RHSA-2026:44480?
You can fix RHSA-2026:44480 by updating the compat-openssl10 package in your Red Hat system.
What issue does RHSA-2026:44480 address?
RHSA-2026:44480 addresses a null pointer dereference vulnerability in the compat-openssl10 package.
On which systems is RHSA-2026:44480 applicable?
RHSA-2026:44480 is applicable to Red Hat Enterprise Linux for x86_64 and Red Hat Enterprise Linux Server.
When was RHSA-2026:44480 published?
RHSA-2026:44480 was published on July 23, 2026.