RHSA-2026:47096: Moderate: compat-openssl10 security update
Moderate: compat-openssl10 security update
Other sources
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries and is provided for compatibility with previous releases and software that does not support compilation with OpenSSL-1.1.Security Fix(es): openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/compat-openssl10to a version that resolves this vulnerability.Fixed in 1.0.2o-3.el8_4.1 - Upgrade
Upgrade
redhat/compat-openssl10-debuginfoto a version that resolves this vulnerability.Fixed in 1.0.2o-3.el8_4.1 - Upgrade
Upgrade
redhat/compat-openssl10-debugsourceto a version that resolves this vulnerability.Fixed in 1.0.2o-3.el8_4.1 - Upgrade
Upgrade
compat-openssl10to a version that resolves this vulnerability.Patch CVE-2026-28390
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:47096?
The severity of RHSA-2026:47096 is classified as medium (4).
How do I fix RHSA-2026:47096?
To fix RHSA-2026:47096, apply the latest compat-openssl10 security update available for your version of Red Hat Enterprise Linux.
What is the risk associated with RHSA-2026:47096?
The risk associated with RHSA-2026:47096 is rated as 19.
What software is affected by RHSA-2026:47096?
The software affected by RHSA-2026:47096 includes Red Hat Enterprise Linux Server and Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life.
When was RHSA-2026:47096 published?
RHSA-2026:47096 was published on July 28, 2026.