compat-openssl11-1.1.1k-5.el9_8.4
エラータID: AXSA:2026-1532:04
リリース日:
2026/08/14 Friday - 10:38
題名:
compat-openssl11-1.1.1k-5.el9_8.4
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- OpenSSL には、メモリ領域の解放後利用の問題があるため、リモート
の攻撃者により、任意のコードの実行、メモリ破壊、およびサービス拒否
攻撃 (クラッシュの発生) を可能とする脆弱性が存在します。
(CVE-2026-45447)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-45447
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. Impact summary: A use-after-free may result in process crashes, heap corruption, or potentially remote code execution. When processing a PKCS#7 or S/MIME signed message, if the SignedData digestAlgorithms field is present as an empty ASN.1 SET, OpenSSL may incorrectly free a caller-owned BIO during PKCS7_verify(). A subsequent use of the BIO by the calling application results in a use-after-free condition. In the common case this occurs when the application later calls BIO_free() on the BIO originally passed to PKCS7_verify(). Depending on allocator behavior and application-specific BIO usage patterns, this may result in a crash or other memory corruption. In some application contexts this may potentially be exploitable for remote code execution. Applications that process PKCS#7 or S/MIME signed messages using OpenSSL PKCS#7 APIs may be affected. Applications using the CMS APIs for this processing are not affected. The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.
追加情報:
N/A
ダウンロード:
SRPMS
- compat-openssl11-1.1.1k-5.el9_8.4.src.rpm
MD5: 2e1ba4ae927464835324a4185d3dffdd
SHA-256: fb546030af58f1f93f0104de2956bcd930b46c9145bf27fd8b3b75b5e8683774
Size: 7.28 MB
Asianux Server 9 for x86_64
- compat-openssl11-1.1.1k-5.el9_8.4.i686.rpm
MD5: 11c1d59e89846de2f46bb7fba2da1538
SHA-256: b7c50646ea7ad5fb123bc83fdfebcb0545b15c230d88088742e8ee9ffa83144b
Size: 1.44 MB - compat-openssl11-1.1.1k-5.el9_8.4.x86_64.rpm
MD5: ff4ddfd70d8da4bd937594ebe5309f44
SHA-256: 458f4e974bf3e3e350236aad27971a16a4bc62cdc63a595acf97c012c8513f9c
Size: 1.45 MB