Release openssl-fips-provider-3.0.7-11.el9_8 ALSA-2026:27744
- Dominant language
- No language data
- Stars
- 2
- Forks
- 0
- PR merge metrics
- No merged PRs in 30d
Description
openssl-fips-provider security update
Severity: Moderate
Description
This package provides a custom build of the OpenSSL FIPS module that has been submitted to NIST for certification.
Security Fix(es):
* openssl: openssl: Information Disclosure from Uninitialized Memory via Invalid RSA Public Key (CVE-2026-31790)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected packages:
openssl-fips-provider-3.0.7-11.el9_8.i686
openssl-fips-provider-3.0.7-11.el9_8.x86_64
openssl-fips-provider-so-3.0.7-11.el9_8.i686
openssl-fips-provider-so-3.0.7-11.el9_8.x86_64
openssl-fips-provider-3.0.7-11.el9_8.s390x
openssl-fips-provider-so-3.0.7-11.el9_8.s390x
openssl-fips-provider-3.0.7-11.el9_8.ppc64le
openssl-fips-provider-so-3.0.7-11.el9_8.ppc64le
openssl-fips-provider-3.0.7-11.el9_8.aarch64
openssl-fips-provider-so-3.0.7-11.el9_8.aarch64
Contributor guide
Assessment
This issue has not been assessed yet.