RHSA-2026:74162

Vulnerability from csaf_redhat - Published: 2026-09-30 23:32 - Updated: 2026-10-02 08:11
Summary
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Severity
Important
Notes
Topic: An update for Red Hat Hardened Images RPMs is now available.
Details: This update includes the following RPMs: openssl: * openssl-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-config-fips-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-devel-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-devel-engine-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-fips-provider-upstream-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-libs-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-perl-3.5.9-0.1.hum1 (aarch64, x86_64) * openssl-3.5.9-0.1.hum1.src (src)
Terms of Use: This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.

A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by presenting a specially crafted certificate during a Transport Layer Security (TLS) handshake. When OpenSSL processes and caches certificate extensions containing numerous Certificate Revocation List (CRL) distribution points, it allocates an excessive amount of memory. This disproportionate memory usage can exhaust system resources and crash the affected client or server application.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Product Identifier Version Remediation
Unresolved product id: Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64 —
Vendor Fix fix
Unresolved product id: Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64 —
Vendor Fix fix
Threats
Impact Low

A flaw was found in OpenSSL. This vulnerability allows a remote attacker to abuse the server to amplify network traffic in a Denial of Service (DoS) attack. When the server is configured without client address validation, incoming datagrams containing multiple QUIC packets cause the server to calculate credit limits incorrectly by adding the total datagram size for each packet. Consequently, the server exceeds standard rate limits and transmits excessive response data to spoofed target addresses.

CWE-358 - Improperly Implemented Security Check for Standard
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Low

A flaw was found in OpenSSL. A remote attacker who establishes a QUIC network connection can cause a Denial of Service (DoS) by sending specially sequenced, out-of-order stream frames. Because the stream reassembly mechanism handles non-sequential data fragments inefficiently, processing these frames forces the server to consume excessive CPU resources. Consequently, an attacker can exhaust system processing capacity using minimal network bandwidth.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. A timing side-channel vulnerability in generic elliptic curve scalar multiplication allows an attacker to recover private cryptographic keys. When performing signature operations, such as the Elliptic Curve Digital Signature Algorithm (ECDSA) or SM2, using curves without dedicated constant-time implementations, variations in processing time leak information about the per-signature secret value. By measuring the duration of numerous signing operations, an attacker can analyze these timing differences to reconstruct the private signing key.

CWE-208 - Observable Timing Discrepancy
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. The optimized scalar point multiplication used for SM2 cryptographic operations on ARM64 and RISC-V architectures does not execute in constant time. An attacker capable of measuring execution times or observing processor cache-access patterns can exploit this side channel during decryption or digital signature generation. This vulnerability allows the attacker to deduce sensitive private keys or signature nonces, leading to information disclosure.

CWE-208 - Observable Timing Discrepancy
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in openssl. When a server replaces its security context during an active Transport Layer Security (TLS) handshake, it fails to update the internal capacity tracking for cryptographic signature algorithms. A remote peer can exploit this issue by advertising specific signature algorithms, causing out-of-bounds memory reads and writes on the server heap. This vulnerability can corrupt internal memory and terminate the process, resulting in a Denial of Service (DoS).

CWE-787 - Out-of-bounds Write
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) due to missing connection-level flow control enforcement in the QUIC protocol implementation. By opening multiple streams that respect individual stream limits while preventing data consumption, the attacker can force the system to buffer far more data than permitted by the connection limit. This excessive memory allocation can exhaust available system resources and degrade or terminate the service.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Important

A flaw was found in OpenSSL. When a Certificate Management Protocol (CMP) client requests certificate revocation using a PKCS#10 Certificate Signing Request (CSR), it omits the certificate issuer name and serial number. A malicious or compromised CMP server, or an attacker possessing valid message protection credentials, can exploit this flaw by returning a crafted revocation response. This triggers a NULL pointer dereference when the client attempts to compare response data, causing the client application to crash and resulting in a Denial of Service (DoS).

CWE-476 - NULL Pointer Dereference
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys.

CWE-1284 - Improper Validation of Specified Quantity in Input
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. During SM2 signature generation, variable-time arithmetic operations are performed on secret values, creating an observable timing side-channel. An attacker capable of measuring signature generation times can collect timing data across multiple signing operations, which may allow them to recover the private key.

CWE-208 - Observable Timing Discrepancy
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate

A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process.

CWE-125 - Out-of-bounds Read
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Important

A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by flooding a connection with connection identifier update requests while withholding acknowledgments. This behavior bypasses connection limits and forces the system to accumulate pending retirement frames, resulting in excessive memory consumption.

CWE-770 - Allocation of Resources Without Limits or Throttling
Affected products
Fixed 15 products, the same list as for CVE-2026-35189
Threats
Impact Moderate
References
URL Category
https://access.redhat.com/errata/RHSA-2026:74162 self
https://images.redhat.com/ external
https://access.redhat.com/security/cve/CVE-2026-75806 external
https://access.redhat.com/security/updates/classi… external
https://access.redhat.com/security/cve/CVE-2026-42772 external
https://access.redhat.com/security/cve/CVE-2026-54875 external
https://access.redhat.com/security/cve/CVE-2026-35189 external
https://access.redhat.com/security/cve/CVE-2026-35191 external
https://access.redhat.com/security/cve/CVE-2026-77696 external
https://access.redhat.com/security/cve/CVE-2026-84784 external
https://access.redhat.com/security/cve/CVE-2026-75804 external
https://access.redhat.com/security/cve/CVE-2026-54873 external
https://access.redhat.com/security/cve/CVE-2026-54872 external
https://access.redhat.com/security/cve/CVE-2026-75805 external
https://access.redhat.com/security/cve/CVE-2026-72897 external
https://access.redhat.com/security/cve/CVE-2026-84782 external
https://security.access.redhat.com/data/csaf/v2/a… self
https://access.redhat.com/security/cve/CVE-2026-35189 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543242 external
https://www.cve.org/CVERecord?id=CVE-2026-35189 external
https://nvd.nist.gov/vuln/detail/CVE-2026-35189 external
https://github.com/openssl/openssl/commit/2b93c73… external
https://github.com/openssl/openssl/commit/3842516… external
https://github.com/openssl/openssl/commit/8e0efc7… external
https://github.com/openssl/openssl/commit/c72ae18… external
https://openssl-library.org/news/secadv/20260929.txt external
https://access.redhat.com/security/cve/CVE-2026-35191 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543257 external
https://www.cve.org/CVERecord?id=CVE-2026-35191 external
https://nvd.nist.gov/vuln/detail/CVE-2026-35191 external
https://github.com/openssl/openssl/commit/0fe4442… external
https://github.com/openssl/openssl/commit/2de4c35… external
https://github.com/openssl/openssl/commit/e44292e… external
https://access.redhat.com/security/cve/CVE-2026-42772 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543249 external
https://www.cve.org/CVERecord?id=CVE-2026-42772 external
https://nvd.nist.gov/vuln/detail/CVE-2026-42772 external
https://github.com/openssl/openssl/commit/32d0ed8… external
https://github.com/openssl/openssl/commit/ca8402e… external
https://github.com/openssl/openssl/commit/eb2becc… external
https://github.com/openssl/openssl/commit/f42ae51… external
https://access.redhat.com/security/cve/CVE-2026-54872 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543250 external
https://www.cve.org/CVERecord?id=CVE-2026-54872 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54872 external
https://github.com/openssl/openssl/commit/1a5bee8… external
https://github.com/openssl/openssl/commit/3f7e136… external
https://github.com/openssl/openssl/commit/7d83bc7… external
https://github.com/openssl/openssl/commit/8166827… external
https://access.redhat.com/security/cve/CVE-2026-54873 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543244 external
https://www.cve.org/CVERecord?id=CVE-2026-54873 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54873 external
https://github.com/openssl/openssl/commit/1f643b8… external
https://github.com/openssl/openssl/commit/279e7ee… external
https://github.com/openssl/openssl/commit/3ea6213… external
https://github.com/openssl/openssl/commit/7127fb1… external
https://access.redhat.com/security/cve/CVE-2026-54875 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543256 external
https://www.cve.org/CVERecord?id=CVE-2026-54875 external
https://nvd.nist.gov/vuln/detail/CVE-2026-54875 external
https://github.com/openssl/openssl/commit/3f01bbc… external
https://github.com/openssl/openssl/commit/469f3e4… external
https://github.com/openssl/openssl/commit/9794ed4… external
https://github.com/openssl/openssl/commit/dddad95… external
https://access.redhat.com/security/cve/CVE-2026-72897 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543259 external
https://www.cve.org/CVERecord?id=CVE-2026-72897 external
https://nvd.nist.gov/vuln/detail/CVE-2026-72897 external
https://github.com/openssl/openssl/commit/00646e5… external
https://github.com/openssl/openssl/commit/4135f55… external
https://github.com/openssl/openssl/commit/9c54d20… external
https://github.com/openssl/openssl/commit/e87ed26… external
https://access.redhat.com/security/cve/CVE-2026-75804 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543254 external
https://www.cve.org/CVERecord?id=CVE-2026-75804 external
https://nvd.nist.gov/vuln/detail/CVE-2026-75804 external
https://github.com/openssl/openssl/commit/2e8f546… external
https://github.com/openssl/openssl/commit/4533ee8… external
https://github.com/openssl/openssl/commit/64d3102… external
https://github.com/openssl/openssl/commit/f9eaecf… external
https://access.redhat.com/security/cve/CVE-2026-75805 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543247 external
https://www.cve.org/CVERecord?id=CVE-2026-75805 external
https://nvd.nist.gov/vuln/detail/CVE-2026-75805 external
https://github.com/openssl/openssl/commit/7588db7… external
https://github.com/openssl/openssl/commit/7ca0ccb… external
https://github.com/openssl/openssl/commit/9eb2a8a… external
https://github.com/openssl/openssl/commit/abf0287… external
https://access.redhat.com/security/cve/CVE-2026-75806 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543260 external
https://www.cve.org/CVERecord?id=CVE-2026-75806 external
https://nvd.nist.gov/vuln/detail/CVE-2026-75806 external
https://github.com/openssl/openssl/commit/04728a2… external
https://github.com/openssl/openssl/commit/050b275… external
https://github.com/openssl/openssl/commit/3a4589d… external
https://github.com/openssl/openssl/commit/5af82fe… external
https://access.redhat.com/security/cve/CVE-2026-77696 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543258 external
https://www.cve.org/CVERecord?id=CVE-2026-77696 external
https://nvd.nist.gov/vuln/detail/CVE-2026-77696 external
https://github.com/openssl/openssl/commit/1c4aed8… external
https://github.com/openssl/openssl/commit/20b2062… external
https://github.com/openssl/openssl/commit/419f5cb… external
https://github.com/openssl/openssl/commit/6b90445… external
https://access.redhat.com/security/cve/CVE-2026-84782 self
https://bugzilla.redhat.com/show_bug.cgi?id=2537080 external
https://www.cve.org/CVERecord?id=CVE-2026-84782 external
https://nvd.nist.gov/vuln/detail/CVE-2026-84782 external
https://openssl-library.org/news/vulnerabilities/… external
https://access.redhat.com/security/cve/CVE-2026-84784 self
https://bugzilla.redhat.com/show_bug.cgi?id=2543261 external
https://www.cve.org/CVERecord?id=CVE-2026-84784 external
https://nvd.nist.gov/vuln/detail/CVE-2026-84784 external
https://github.com/openssl/openssl/commit/4685c91… external
https://github.com/openssl/openssl/commit/9a30fe0… external
https://github.com/openssl/openssl/commit/dba3c48… external
https://github.com/openssl/openssl/commit/e9e5155… external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright \u00a9 Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "An update for Red Hat Hardened Images RPMs is now available.",
        "title": "Topic"
      },
      {
        "category": "general",
        "text": "This update includes the following RPMs:\n\nopenssl:\n  * openssl-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-config-fips-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-devel-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-devel-engine-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-fips-provider-upstream-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-libs-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-perl-3.5.9-0.1.hum1 (aarch64, x86_64)\n  * openssl-3.5.9-0.1.hum1.src (src)",
        "title": "Details"
      },
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://access.redhat.com/errata/RHSA-2026:74162",
        "url": "https://access.redhat.com/errata/RHSA-2026:74162"
      },
      {
        "category": "external",
        "summary": "https://images.redhat.com/",
        "url": "https://images.redhat.com/"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-75806",
        "url": "https://access.redhat.com/security/cve/CVE-2026-75806"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/updates/classification/",
        "url": "https://access.redhat.com/security/updates/classification/"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-42772",
        "url": "https://access.redhat.com/security/cve/CVE-2026-42772"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-54875",
        "url": "https://access.redhat.com/security/cve/CVE-2026-54875"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-35189",
        "url": "https://access.redhat.com/security/cve/CVE-2026-35189"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-35191",
        "url": "https://access.redhat.com/security/cve/CVE-2026-35191"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-77696",
        "url": "https://access.redhat.com/security/cve/CVE-2026-77696"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-84784",
        "url": "https://access.redhat.com/security/cve/CVE-2026-84784"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-75804",
        "url": "https://access.redhat.com/security/cve/CVE-2026-75804"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-54873",
        "url": "https://access.redhat.com/security/cve/CVE-2026-54873"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-54872",
        "url": "https://access.redhat.com/security/cve/CVE-2026-54872"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-75805",
        "url": "https://access.redhat.com/security/cve/CVE-2026-75805"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-72897",
        "url": "https://access.redhat.com/security/cve/CVE-2026-72897"
      },
      {
        "category": "external",
        "summary": "https://access.redhat.com/security/cve/CVE-2026-84782",
        "url": "https://access.redhat.com/security/cve/CVE-2026-84782"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_74162.json"
      }
    ],
    "title": "Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update",
    "tracking": {
      "current_release_date": "2026-10-02T08:11:47+00:00",
      "generator": {
        "date": "2026-10-02T08:11:47+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.4.0"
        }
      },
      "id": "RHSA-2026:74162",
      "initial_release_date": "2026-09-30T23:32:42+00:00",
      "revision_history": [
        {
          "date": "2026-09-30T23:32:42+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-10-01T00:20:02+00:00",
          "number": "2",
          "summary": "Last updated version"
        },
        {
          "date": "2026-10-02T08:11:47+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Hardened Images",
                "product": {
                  "name": "Red Hat Hardened Images",
                  "product_id": "Red Hat Hardened Images",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:hummingbird:1"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Hardened Images"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-config-fips@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-devel-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-devel-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel-engine@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-fips-provider-upstream@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-libs-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-libs-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-0:3.5.9-0.1.hum1@aarch64",
                "product": {
                  "name": "openssl-perl-0:3.5.9-0.1.hum1@aarch64",
                  "product_id": "openssl-perl-0:3.5.9-0.1.hum1@aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@3.5.9-0.1.hum1?arch=aarch64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-aarch64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:3.5.9-0.1.hum1@src",
                "product": {
                  "name": "openssl-0:3.5.9-0.1.hum1@src",
                  "product_id": "openssl-0:3.5.9-0.1.hum1@src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.9-0.1.hum1?arch=src\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-source-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "openssl-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-config-fips@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-devel-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-devel-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-devel-engine@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-fips-provider-upstream@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-libs-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-libs-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-libs-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-libs@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "openssl-perl-0:3.5.9-0.1.hum1@x86_64",
                "product": {
                  "name": "openssl-perl-0:3.5.9-0.1.hum1@x86_64",
                  "product_id": "openssl-perl-0:3.5.9-0.1.hum1@x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/openssl-perl@3.5.9-0.1.hum1?arch=x86_64\u0026distro=hummingbird-20251124\u0026repository_id=public-hummingbird-x86_64-rpms"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:3.5.9-0.1.hum1@src as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src"
        },
        "product_reference": "openssl-0:3.5.9-0.1.hum1@src",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-config-fips-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-config-fips-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-devel-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-devel-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-libs-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-libs-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-libs-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-0:3.5.9-0.1.hum1@aarch64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64"
        },
        "product_reference": "openssl-perl-0:3.5.9-0.1.hum1@aarch64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "openssl-perl-0:3.5.9-0.1.hum1@x86_64 as a component of Red Hat Hardened Images",
          "product_id": "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        },
        "product_reference": "openssl-perl-0:3.5.9-0.1.hum1@x86_64",
        "relates_to_product_reference": "Red Hat Hardened Images"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-35189",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-09-29T15:40:58.439166+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543242"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by presenting a specially crafted certificate during a Transport Layer Security (TLS) handshake. When OpenSSL processes and caches certificate extensions containing numerous Certificate Revocation List (CRL) distribution points, it allocates an excessive amount of memory. This disproportionate memory usage can exhaust system resources and crash the affected client or server application.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-35189"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543242",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543242"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-35189",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35189"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-35189",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35189"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84",
          "url": "https://github.com/openssl/openssl/commit/2b93c73b2c70ddc4c61c5e4bfaaa6bd71379eb84"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89",
          "url": "https://github.com/openssl/openssl/commit/3842516cc15e8b2cf55747011045e77547e71d89"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f",
          "url": "https://github.com/openssl/openssl/commit/8e0efc7549b7ff8246d40e585e3fd604f728473f"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9",
          "url": "https://github.com/openssl/openssl/commit/c72ae182cac17a82e4246c6ecd4e9c4ec3586ec9"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:11.889000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: openssl: Denial of Service via excessive memory allocation in CRL distribution point processing"
    },
    {
      "cve": "CVE-2026-35191",
      "cwe": {
        "id": "CWE-358",
        "name": "Improperly Implemented Security Check for Standard"
      },
      "discovery_date": "2026-09-29T15:45:05.189110+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543257"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. This vulnerability allows a remote attacker to abuse the server to amplify network traffic in a Denial of Service (DoS) attack. When the server is configured without client address validation, incoming datagrams containing multiple QUIC packets cause the server to calculate credit limits incorrectly by adding the total datagram size for each packet. Consequently, the server exceeds standard rate limits and transmits excessive response data to spoofed target addresses.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-35191"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543257",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543257"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-35191",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-35191"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-35191",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-35191"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239",
          "url": "https://github.com/openssl/openssl/commit/0fe4442d4f8ea3af8a174046dae176e0d4717239"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5",
          "url": "https://github.com/openssl/openssl/commit/2de4c35fb13fc58f43fd8dc1d261700472ce72e5"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a",
          "url": "https://github.com/openssl/openssl/commit/e44292e58b090014232ef75bd400393851b24d1a"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:12.944000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ],
      "title": "openssl: openssl: Traffic amplification Denial of Service via QUIC packet over-accounting"
    },
    {
      "cve": "CVE-2026-42772",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-09-29T15:43:05.448900+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543249"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote attacker who establishes a QUIC network connection can cause a Denial of Service (DoS) by sending specially sequenced, out-of-order stream frames. Because the stream reassembly mechanism handles non-sequential data fragments inefficiently, processing these frames forces the server to consume excessive CPU resources. Consequently, an attacker can exhaust system processing capacity using minimal network bandwidth.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: Denial of Service via inefficient QUIC stream reassembly",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-42772"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543249",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543249"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-42772",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42772"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-42772",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-42772"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09",
          "url": "https://github.com/openssl/openssl/commit/32d0ed8afe1b8c3e7ece725b44663da3d7087a09"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e",
          "url": "https://github.com/openssl/openssl/commit/ca8402e273af4de5b3f04fa61a0f0c02ce3ae20e"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773",
          "url": "https://github.com/openssl/openssl/commit/eb2becc0a4baea7f3050a247834d0e5c2ebe1773"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a",
          "url": "https://github.com/openssl/openssl/commit/f42ae513bbda513b3c121d54834040ee4a0eae1a"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:14.009000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: openssl: Denial of Service via inefficient QUIC stream reassembly"
    },
    {
      "cve": "CVE-2026-54872",
      "cwe": {
        "id": "CWE-208",
        "name": "Observable Timing Discrepancy"
      },
      "discovery_date": "2026-09-29T15:43:26.231574+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543250"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A timing side-channel vulnerability in generic elliptic curve scalar multiplication allows an attacker to recover private cryptographic keys. When performing signature operations, such as the Elliptic Curve Digital Signature Algorithm (ECDSA) or SM2, using curves without dedicated constant-time implementations, variations in processing time leak information about the per-signature secret value. By measuring the duration of numerous signing operations, an attacker can analyze these timing differences to reconstruct the private signing key.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-54872"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543250",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543250"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-54872",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54872"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-54872",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54872"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179",
          "url": "https://github.com/openssl/openssl/commit/1a5bee8dc57430a2be69cd1ffe7fec6a62f4f179"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb",
          "url": "https://github.com/openssl/openssl/commit/3f7e1363dccec6f7732bb9e9fa471bb6e4aa68cb"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd",
          "url": "https://github.com/openssl/openssl/commit/7d83bc7764999dfd91b83b4f0815b45390422afd"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471",
          "url": "https://github.com/openssl/openssl/commit/8166827a78aad164a07aa86dea2b425403ced471"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:15.075000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: OpenSSL: Private key recovery via timing side-channel in generic elliptic curve operations"
    },
    {
      "cve": "CVE-2026-54873",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-09-29T15:42:01.399421+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543244"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by sending specially crafted network packets to a QUIC protocol endpoint. Because the QUIC stack retains memory in packet buffers until the receiving application reads the stream data, an attacker can manipulate data transfers to keep these buffers allocated indefinitely. This behavior leads to excessive memory consumption and can exhaust available system resources.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: Denial of Service via excessive QUIC packet buffer retention",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-54873"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543244",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543244"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-54873",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54873"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-54873",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54873"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23",
          "url": "https://github.com/openssl/openssl/commit/1f643b8bc735487b500a1f68a7fb3a22d5e38e23"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53",
          "url": "https://github.com/openssl/openssl/commit/279e7ee1392af98785746788168749491c74bd53"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb",
          "url": "https://github.com/openssl/openssl/commit/3ea6213e050e938ecbbf8c4eff32bec2736780eb"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2",
          "url": "https://github.com/openssl/openssl/commit/7127fb10888b49711c63128a09e524c0d2d5d0b2"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:16.134000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: openssl: Denial of Service via excessive QUIC packet buffer retention"
    },
    {
      "cve": "CVE-2026-54875",
      "cwe": {
        "id": "CWE-208",
        "name": "Observable Timing Discrepancy"
      },
      "discovery_date": "2026-09-29T15:44:46.989865+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543256"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. The optimized scalar point multiplication used for SM2 cryptographic operations on ARM64 and RISC-V architectures does not execute in constant time. An attacker capable of measuring execution times or observing processor cache-access patterns can exploit this side channel during decryption or digital signature generation. This vulnerability allows the attacker to deduce sensitive private keys or signature nonces, leading to information disclosure.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-54875"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543256",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543256"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-54875",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-54875"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-54875",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-54875"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257",
          "url": "https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8",
          "url": "https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28",
          "url": "https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c",
          "url": "https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:17.206000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "LOCAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: openssl: information disclosure via non-constant-time SM2 scalar multiplication on ARM64 and RISC-V"
    },
    {
      "cve": "CVE-2026-72897",
      "cwe": {
        "id": "CWE-787",
        "name": "Out-of-bounds Write"
      },
      "discovery_date": "2026-09-29T15:45:23.368533+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543259"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in openssl. When a server replaces its security context during an active Transport Layer Security (TLS) handshake, it fails to update the internal capacity tracking for cryptographic signature algorithms. A remote peer can exploit this issue by advertising specific signature algorithms, causing out-of-bounds memory reads and writes on the server heap. This vulnerability can corrupt internal memory and terminate the process, resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-72897"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543259",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543259"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-72897",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-72897"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-72897",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-72897"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922",
          "url": "https://github.com/openssl/openssl/commit/00646e5085a0d12d29e0d2f9b9bc5f7111a50922"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e",
          "url": "https://github.com/openssl/openssl/commit/4135f553c9d3ba4a09fe752f5d30af2a6a092b2e"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61",
          "url": "https://github.com/openssl/openssl/commit/9c54d209486f6b1ad79fe2179c40f13200fa4f61"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814",
          "url": "https://github.com/openssl/openssl/commit/e87ed26b298a74d8ba61a53e9c7bcd1acac6b814"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:18.277000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: openssl: Denial of Service via out-of-bounds write during TLS context switch"
    },
    {
      "cve": "CVE-2026-75804",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-09-29T15:44:05.088871+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543254"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) due to missing connection-level flow control enforcement in the QUIC protocol implementation. By opening multiple streams that respect individual stream limits while preventing data consumption, the attacker can force the system to buffer far more data than permitted by the connection limit. This excessive memory allocation can exhaust available system resources and degrade or terminate the service.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-75804"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543254",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543254"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-75804",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75804"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-75804",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75804"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e",
          "url": "https://github.com/openssl/openssl/commit/2e8f54666b3fb7b05ff5f58aa6cac9285163654e"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538",
          "url": "https://github.com/openssl/openssl/commit/4533ee8a5686c953ed3b644738ac4bdf20806538"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a",
          "url": "https://github.com/openssl/openssl/commit/64d3102fb5b54311e92517f26ba00169d719e74a"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03",
          "url": "https://github.com/openssl/openssl/commit/f9eaecf5bdd6692da052bc65b0332af2a938ac03"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:19.335000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "openssl: OpenSSL: Denial of Service via unenforced QUIC connection flow control"
    },
    {
      "cve": "CVE-2026-75805",
      "cwe": {
        "id": "CWE-476",
        "name": "NULL Pointer Dereference"
      },
      "discovery_date": "2026-09-29T15:42:45.197681+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543247"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. When a Certificate Management Protocol (CMP) client requests certificate revocation using a PKCS#10 Certificate Signing Request (CSR), it omits the certificate issuer name and serial number. A malicious or compromised CMP server, or an attacker possessing valid message protection credentials, can exploit this flaw by returning a crafted revocation response. This triggers a NULL pointer dereference when the client attempts to compare response data, causing the client application to crash and resulting in a Denial of Service (DoS).",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: openssl: Denial of Service via crafted CMP certificate revocation response",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This flaw is rated Moderate. It is a Denial of Service only: a CMP client can crash when processing a crafted certificate revocation response after requesting revocation with a PKCS#10 CSR. Exploitation requires a malicious or compromised CMP server, or a man-in-the-middle that already has the CMP message-protection secret. There is no confidentiality or integrity impact, FIPS modules are not affected, and clients that identify the certificate by certificate or by issuer and serial number are not affected.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-75805"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543247",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543247"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-75805",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75805"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-75805",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75805"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166",
          "url": "https://github.com/openssl/openssl/commit/7588db7fef14209c3caa3a101d11a02006b19166"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7",
          "url": "https://github.com/openssl/openssl/commit/7ca0ccb5172a577e9b87267d77bfe21e5481a5e7"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3",
          "url": "https://github.com/openssl/openssl/commit/9eb2a8a9b86136cdb39d6d7d50644dd66941cdc3"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f",
          "url": "https://github.com/openssl/openssl/commit/abf02872a4b71767ecc72293424420f5b009190f"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:20.408000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        },
        {
          "category": "workaround",
          "details": "Do not revoke certificates over CMP by supplying a PKCS#10 CSR (`openssl cmp -cmd rr -csr ...` or `OSSL_CMP_CTX_set1_p10CSR()`). Identify the certificate by certificate or by issuer name and serial number instead. Restrict CMP clients to trusted CMP servers and protect CMP message-protection credentials. If CMP certificate revocation is unused, avoid enabling CMP client revocation workflows.",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: openssl: Denial of Service via crafted CMP certificate revocation response"
    },
    {
      "cve": "CVE-2026-75806",
      "cwe": {
        "id": "CWE-1284",
        "name": "Improper Validation of Specified Quantity in Input"
      },
      "discovery_date": "2026-09-29T15:45:42.068952+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543260"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote, unauthenticated attacker can cause a Denial of Service (DoS) by terminating an active Datagram Transport Layer Security (DTLS) session. By sending an undersized network packet that is shorter than the expected cryptographic overhead, the record processing layer fails to validate the packet length and misinterprets the packet as an internal error rather than an authentication failure. This improper handling triggers a fatal alert that unexpectedly closes the targeted connection without requiring valid encryption keys.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Denial of Service via undersized DTLS record",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-75806"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543260",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543260"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-75806",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-75806"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-75806",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-75806"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d",
          "url": "https://github.com/openssl/openssl/commit/04728a289a823e68137f88da016cb9ede307217d"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972",
          "url": "https://github.com/openssl/openssl/commit/050b275cd671a6eed1d6457642d41a5a77aab972"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d",
          "url": "https://github.com/openssl/openssl/commit/3a4589d015a9049d47b66f186cf50a8711343a1d"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d",
          "url": "https://github.com/openssl/openssl/commit/5af82fefbaf2b5fec2fc0e1d87f112844902f01d"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:21.457000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: OpenSSL: Denial of Service via undersized DTLS record"
    },
    {
      "cve": "CVE-2026-77696",
      "cwe": {
        "id": "CWE-208",
        "name": "Observable Timing Discrepancy"
      },
      "discovery_date": "2026-09-29T15:46:01.508728+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543258"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. During SM2 signature generation, variable-time arithmetic operations are performed on secret values, creating an observable timing side-channel. An attacker capable of measuring signature generation times can collect timing data across multiple signing operations, which may allow them to recover the private key.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Private key recovery via SM2 timing side-channel",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-77696"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543258",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543258"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-77696",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77696"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-77696",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77696"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9",
          "url": "https://github.com/openssl/openssl/commit/1c4aed808a7aea32d2d013049c2e0d9fef164fc9"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb",
          "url": "https://github.com/openssl/openssl/commit/20b20628d39b2dcc4677194bd68c7c060fa598cb"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64",
          "url": "https://github.com/openssl/openssl/commit/419f5cb519721dceed393dbc524d79e487c72e64"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440",
          "url": "https://github.com/openssl/openssl/commit/6b90445a56b99a328ac1feba058abf976504f440"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:22.520000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: OpenSSL: Private key recovery via SM2 timing side-channel"
    },
    {
      "cve": "CVE-2026-84782",
      "cwe": {
        "id": "CWE-125",
        "name": "Out-of-bounds Read"
      },
      "discovery_date": "2026-09-18T19:58:21.939000+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2537080"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. The Datagram Transport Layer Security (DTLS) retransmission mechanism fails to properly handle handshake message writes that are suspended before completion. A remote attacker could exploit this vulnerability during handshake message retransmission, causing OpenSSL to read past the message buffer or overwrite internal state required to resume writing. This issue can result in information disclosure through out-of-bounds memory reads or cause a Denial of Service (DoS) by crashing the process.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "This vulnerability is rated as an Important severity because an unauthenticated network adversary can trigger process crashes or memory exposure without requiring local system privileges. Red Hat Enterprise Linux utilizes OpenSSL as the fundamental cryptographic provider across the operating system; however, overall exposure is limited because the flaw strictly affects software using Datagram Transport Layer Security (DTLS) over UDP under non-blocking I/O configurations. Standard TLS connections over TCP, which represent the typical deployment model for the majority of Red Hat workloads and system services, are unaffected.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-84782"
        },
        {
          "category": "external",
          "summary": "RHBZ#2537080",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2537080"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-84782",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84782"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-84782",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84782"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782",
          "url": "https://openssl-library.org/news/vulnerabilities/#CVE-2026-84782"
        }
      ],
      "release_date": "2026-09-29T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ],
      "title": "openssl: compat-openssl: openssl: Information disclosure via DTLS handshake retransmission"
    },
    {
      "cve": "CVE-2026-84784",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2026-09-29T15:46:18.639012+00:00",
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2543261"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "A flaw was found in OpenSSL. A remote attacker can cause a Denial of Service (DoS) by flooding a connection with connection identifier update requests while withholding acknowledgments. This behavior bypasses connection limits and forces the system to accumulate pending retirement frames, resulting in excessive memory consumption.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product\u0027s status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
          "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
          "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2026-84784"
        },
        {
          "category": "external",
          "summary": "RHBZ#2543261",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2543261"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2026-84784",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-84784"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2026-84784",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84784"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a",
          "url": "https://github.com/openssl/openssl/commit/4685c914b0d410b1034f40b547c95bc95e7a380a"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806",
          "url": "https://github.com/openssl/openssl/commit/9a30fe0fba195c14e5b87bf93c0d0fdb70373806"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f",
          "url": "https://github.com/openssl/openssl/commit/dba3c48d653c64fcbc9070a17a0ee2b3e2f3af1f"
        },
        {
          "category": "external",
          "summary": "https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe",
          "url": "https://github.com/openssl/openssl/commit/e9e5155833fa968bee50024bf9ca3a185ab599fe"
        },
        {
          "category": "external",
          "summary": "https://openssl-library.org/news/secadv/20260929.txt",
          "url": "https://openssl-library.org/news/secadv/20260929.txt"
        }
      ],
      "release_date": "2026-09-29T15:32:25.758000+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-30T23:32:42+00:00",
          "details": "For details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/",
          "product_ids": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ],
          "restart_required": {
            "category": "none"
          },
          "url": "https://access.redhat.com/errata/RHSA-2026:74162"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@src",
            "Red Hat Hardened Images:openssl-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-config-fips-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-devel-engine-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-fips-provider-upstream-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-libs-0:3.5.9-0.1.hum1@x86_64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@aarch64",
            "Red Hat Hardened Images:openssl-perl-0:3.5.9-0.1.hum1@x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ],
      "title": "openssl: OpenSSL: Denial of Service via unbounded QUIC connection identifier backlog"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…