compat-openssl11-1.1.1k-5.el9_8.3
エラータID: AXSA:2026-1291:03
The OpenSSL toolkit provides support for secure communications between machines. This version of OpenSSL package contains only the libraries from the 1.1.1 version and is provided for compatibility with previous releases.
Security Fix(es):
* openssl: OpenSSL: Denial of Service due to NULL pointer dereference in CMS EnvelopedData processing (CVE-2026-28390)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-28390
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Update packages.
Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-controlled CMS data may crash before authentication or cryptographic operations occur resulting in Denial of Service. When a CMS EnvelopedData message that uses KeyTransportRecipientInfo with RSA-OAEP encryption is processed, the optional parameters field of RSA-OAEP SourceFunc algorithm identifier is examined without checking for its presence. This results in a NULL pointer dereference if the field is missing. Applications and services that call CMS_decrypt() on untrusted input (e.g., S/MIME processing or CMS-based protocols) are vulnerable. The FIPS modules in 3.6, 3.5, 3.4, 3.3 and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
N/A
SRPMS
- compat-openssl11-1.1.1k-5.el9_8.3.src.rpm
MD5: 489b1c9795fd452c12a250a8281c7a7a
SHA-256: 69ab988be6bb8a17d9adf282896a736307798a8412ac45fa8b70bacc315106ee
Size: 7.28 MB
Asianux Server 9 for x86_64
- compat-openssl11-1.1.1k-5.el9_8.3.i686.rpm
MD5: e53c57b63039b7c3f627a13d2517c265
SHA-256: ccccdb5f92a03073a11ea8eb84ac062d816aec12c11a0f1d1bf5359cf564ab59
Size: 1.44 MB - compat-openssl11-1.1.1k-5.el9_8.3.x86_64.rpm
MD5: 1a55f6636cacf52e97ddec7a9b4a509e
SHA-256: d2a07dfc4b64891dcbbc53558e1470268762cd0c6b623b064fcd29bde4382ab6
Size: 1.45 MB