Resource exhaustion in OpenSSL - CVE-2023-0464
Published: March 22, 2023 / Updated: May 30, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when verifying X.509 certificate chains that include policy constraints. A remote attacker can create a specially crafted certificate to trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Isolation Segment
VMware Tanzu Application Service for VMs
Data Lakehouse
cert-manager Operator for Red Hat OpenShift
Dell Secure Connect Gateway
IBM Rational Build Forge
IBM QRadar WinCollect Agent
NetWorker
IBM Spectrum Conductor
IBM Cloud Transformation Advisor
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Safer Payments
IBM Spectrum Symphony
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Spectrum Protect Plus
InfoSphere Master Data Management
PowerProtect Data Manager
Amazon Linux AMI
Oracle Linux
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
Legacy Module
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 12 SP4 LTSS
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Junos OS Evolved
Cisco NX-OS
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
HP-UX OpenSSL
cflinuxfs3
Pair
ObjectScale
Storage Defender – Data Protect
Secured Component Verification (SCV)
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Events Operator
MobileFirst Platform
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
IBM Workload Automation
Cognos Transformer
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
API Gateway
JBoss Core Services
API Manager
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
Oracle VM VirtualBox
VMware Tanzu Operations Manager
Argo CD
Network Observability plugin for the Openshift Console
Red Hat OpenShift Container Platform
IBM Watson Explorer Foundational Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
VMware Horizon Client
JBoss Web Server
Zimbra Collaboration
IBM InfoSphere Information Server
Cisco Jabber
Cisco Webex Meetings
libssl1.0.0 (Ubuntu package)
libssl-doc (Ubuntu package)
openssl (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
openssl-doc
libopenssl0_9_8-hmac
openssl
libopenssl0_9_8
libopenssl0_9_8-32bit
libopenssl0_9_8-hmac-32bit
libopenssl0_9_8-debuginfo
libopenssl0_9_8-debuginfo-32bit
compat-openssl098-debugsource
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0-32bit
openssl1-doc
libopenssl1_0_0
libopenssl1-devel
openssl1
libopenssl1_0_0-debuginfo
openssl-debuginfo
libopenssl1_0_0-debuginfo-32bit
openssl-debugsource
libopenssl-devel
libopenssl1_0_0-hmac
libopenssl1_0_0-hmac-32bit
openssl-1_0_0
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-doc
libopenssl-1_0_0-devel
openssl-1_0_0-debugsource
openssl-1_0_0-debuginfo
openssl1.0 (Ubuntu package)
libopenssl1_0_0-steam-debuginfo
libopenssl1_0_0-steam
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-32bit-debuginfo
openssl-1_0_0-cavs-debuginfo
libopenssl10
libopenssl10-debuginfo
openssl-1_0_0-cavs
openssl-1_1-debugsource
libopenssl1_1-hmac
openssl-1_1
libopenssl1_1
libopenssl1_1-debuginfo
openssl-1_1-debuginfo
libopenssl-1_1-devel
libopenssl1_1-32bit-debuginfo
libopenssl1_1-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-hmac-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-help
openssl-devel
openssl-libs
libssl1.1 (Ubuntu package)
openssl (Debian package)
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
openssl-3
libopenssl3-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
libopenssl3-32bit-debuginfo
openssl-3-doc
openssl-3-debuginfo
libopenssl3
openssl-3-debugsource
libopenssl-3-devel
libssl3 (Ubuntu package)
openssl (Red Hat package)
dev-libs/openssl
npm
v8-devel
jbcs-httpd24-curl (Red Hat package)
jws5-tomcat (Red Hat package)
nodejs-docs
nodejs-debuginfo
nodejs-devel
nodejs-libs
nodejs-full-i18n
nodejs-debugsource
nodejs
shim-debugsource
shim-debuginfo
shim
edk2 (Ubuntu package)
edk2
edk2-debuginfo
edk2-devel
edk2-debugsource
edk2-help
python3-edk2-devel
edk2-aarch64
edk2-ovmf
SINEC INS
Dell G15 5511
Alienware m15 R6
XPS 8960
FOS Firmware
IBM Cloud Pak System
TeleControl Server Basic
Event Streams
NetWorker Management Console
SCALANCE XR552-12M
SCALANCE XR528-6M
SCALANCE XR526-8C
SCALANCE XR524-8C
SCALANCE XM416-4C
SCALANCE XM408-8C
SCALANCE XM408-4C
IBM Security Verify Access
IBM CICS TX Advanced
IBM Cognos Analytics
How to mitigate CVE-2023-0464
API Gateway - addressed in versions August 2023, May 2023
API Manager - addressed in versions August 2023, May 2023
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift sandboxed containers - update to 1.4.1
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
Argo CD - update to 2.6.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
JBoss Web Server - update to 5.7.7
Dell Secure Connect Gateway - update to 5.16
Oracle VM VirtualBox - addressed in versions 6.1.46, 7.0.10
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.25
Zimbra Collaboration - addressed in versions 8.8.15 Patch 41, 9.0.0 Patch 34, 10.0.2
IBM QRadar WinCollect Agent - update to 10.1.6
IBM Watson Explorer Foundational Components - update to 11.0.2.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.10.0.0, 19.11.0.3, 19.11.0.6, 19.12.0.0, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2n-1ubuntu5.12
libssl-doc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
HP-UX OpenSSL - update to A.01.01.01w.001
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
openssl-doc - addressed in versions 0.9.8j-0.106.63.1, 1.0.2j-60.89.1
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.63.1
openssl - addressed in versions 0.9.8j-0.106.63.1, 1.0.2j-60.89.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.63.1, 0.9.8j-106.45.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.63.1, 0.9.8j-106.45.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.63.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.45.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.45.1
compat-openssl098-debugsource - update to 0.9.8j-106.45.1
cflinuxfs3 - update to 0.364.0
SINEC INS - update to 1.0 SP2 Update 2
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.59.1, 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl1-doc - update to 1.0.1g-0.58.59.1
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.59.1, 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl1-devel - update to 1.0.1g-0.58.59.1
openssl1 - update to 1.0.1g-0.58.59.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-debuginfo - update to 1.0.2j-60.89.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1
openssl-debugsource - update to 1.0.2j-60.89.1
libopenssl-devel - update to 1.0.2j-60.89.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl-1_0_0-devel-32bit - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0-doc - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl1.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.12
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.70.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.70.1
libopenssl10 - update to 1.0.2p-150000.3.70.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.70.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.70.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-hmac - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
openssl-1_1 - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1 - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl-1_1-devel - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-32bit - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.78.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
openssl-debuginfo - update to 1.1.1f-23
openssl-debugsource - update to 1.1.1f-23
openssl-help - update to 1.1.1f-23
openssl-devel - update to 1.1.1f-23
openssl-libs - update to 1.1.1f-23
openssl - update to 1.1.1f-23
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22
openssl (Debian package) - update to 1.1.1n-0+deb11u5
Pair - update to 1.2.3
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-16.redhat_16.el7jws, 1.2.31-16.redhat_16.el8jws, 1.2.31-16.redhat_16.el9jws
Network Observability plugin for the Openshift Console - update to 1.3.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.1
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
XPS 8960 - update to 2.3.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
IBM Spectrum Conductor - update to 2.5.1 FP2
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
VMware Tanzu Operations Manager - addressed in versions 2.10.57, 3.0.8
openssl-3 - update to 3.0.1-150400.4.20.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.20.1
libopenssl3-32bit - update to 3.0.1-150400.4.20.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.20.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.20.1
openssl-3-doc - update to 3.0.1-150400.4.20.1
openssl-3-debuginfo - update to 3.0.1-150400.4.20.1
libopenssl3 - update to 3.0.1-150400.4.20.1
openssl-3-debugsource - update to 3.0.1-150400.4.20.1
libopenssl-3-devel - update to 3.0.1-150400.4.20.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl (Red Hat package) - update to 3.0.7-16.el9_2
openssl - update to 3.0.8-1
dev-libs/openssl - update to 3.0.10
TeleControl Server Basic - update to 3.1.2
IBM Cloud Transformation Advisor - update to 3.5.2
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
Enterprise SONiC - update to 4.1.2
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Events Operator - update to 5.1.0
IBM Spectrum Control - update to 5.4.10.2
IBM Safer Payments - addressed in versions 6.3.1.05, 6.4.2.04, 6.5.0.02
SCALANCE XR552-12M - update to 6.6.1
SCALANCE XR528-6M - update to 6.6.1
SCALANCE XR526-8C - update to 6.6.1
SCALANCE XR524-8C - update to 6.6.1
SCALANCE XM416-4C - update to 6.6.1
SCALANCE XM408-8C - update to 6.6.1
SCALANCE XM408-4C - update to 6.6.1
npm - addressed in versions 6.14.16-1.12.22.11.7, 6.14.16-1.12.22.11.9
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
v8-devel - addressed in versions 7.8.279.23-1.12.22.11.7, 7.8.279.23-1.12.22.11.9
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202307260922
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM Rational ClearCase - addressed in versions 9.0.2.8, 9.1.0.5
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-19.redhat_00017.1.el7jws, 9.0.62-19.redhat_00017.1.el8jws, 9.0.62-19.redhat_00017.1.el9jws
FOS Firmware - addressed in versions 9.2.0b, 9.2.1
Cisco NX-OS - update to 9.4(1a)
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.4
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - update to 10.1.0.0 ifix18
IBM Spectrum Protect Plus - update to 10.1.15
Cognos Transformer - update to 11.1.7 Fix Pack 8
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Event Streams - update to 11.5.1
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
nodejs-docs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debuginfo - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-devel - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-libs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-full-i18n - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debugsource - addressed in versions 12.22.11-7, 12.22.11-9
nodejs - addressed in versions 12.22.11-7, 12.22.11-9
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
shim-debugsource - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15-28
shim-debuginfo - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15-28
shim - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15-28
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202002-18
edk2-debuginfo - update to 202002-18
edk2-devel - update to 202002-18
edk2-debugsource - update to 202002-18
edk2-help - update to 202002-18
python3-edk2-devel - update to 202002-18
edk2-aarch64 - update to 202002-18
edk2-ovmf - update to 202002-18
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSL
- SUSE update for openssl-1_0_0
- SUSE update for openssl-1_0_0
- SUSE update for openssl
- SUSE update for compat-openssl098
- SUSE update for openssl-1_1
- SUSE update for openssl-1_1
- SUSE update for openssl-3
- SUSE update for openssl-1_1
- SUSE update for openssl1
- SUSE update for openssl
- SUSE update for openssl-1_1
- Cloud Foundry Foundation cflinuxfs3 update for OpenSSL
- Ubuntu update for openssl
- Multiple vulnerabilities in IBM i
- Multiple vulnerabilities in Dell Cloud Tiering Appliance
- Denial of service in Argo CD
- VMware Tanzu products update for OpenSSL
- Multiple vulnerabilities in IBM Cloud Transformation Advisor
- Debian update for openssl
- Multiple vulnerabilities in Axway API Gateway and API Manager
- Amazon Linux AMI update for openssl
- Resource exhaustion in IBM CICS TX Advanced
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Red Hat Enterprise Linux 9 update for openssl
- Multiple vulnerabilities in Network Observability plugin for the Openshift Console
- Multiple vulnerabilities in IBM Watson Explorer
- Multiple vulnerabilities in OpenShift Container Platform 4.12
- Multiple vulnerabilities in Oracle VM VirtualBox
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM QRadar Wincollect
- Multiple vulnerabilities in Zimbra Collaboration
- Multiple vulnerabilities in Dell PowerProtect Cyber Recovery
- Multiple vulnerabilities in OpenShift sandboxed containers 1.4
- Multiple vulnerabilities in OpenShift Container Platform 4.13
- Multiple vulnerabilities in IBM Safer Payments
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in cert-manager Operator for Red Hat OpenShift
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in IBM MobileFirst Platform
- Multiple vulnerabilities in Dell Data Protection Central
- Axway API Gateway and API Manager update for OpenSSL
- Multiple vulnerabilities in IBM Rational ClearCase
- Multiple vulnerabilities in IBM Rational ClearQuest
- Multiple vulnerabilities in IBM Spectrum Conductor
- Multiple vulnerabilities in IBM Spectrum Symphony
- Multiple vulnerabilities in IBM Spectrum Control
- Resource exhaustion in IBM Tivoli Netcool System Service Monitors/Application Service Monitors
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in IBM Storage Defender - Data Protect
- Denial of service in HP-UX OpenSSL
- Multiple vulnerabilities in IBM Rational Build Forge
- IBM InfoSphere Information Server update for OpenSSL
- Multiple vulnerabilities in Dell EMC Enterprise SONiC
- Multiple vulnerabilities in Red Hat JBoss Web Server 5.7
- Multiple vulnerabilities in JBoss Enterprise Web Server 5 for RHEL 7, 8, and 9
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server 2.4
- Multiple vulnerabilities in Red Hat JBoss Core Services for RHEL 7 and 8
- Multiple vulnerabilities in Siemens SINEC INS
- Multiple vulnerabilities in Dell Networker
- Dell Platform BIOS update for OpenSSL
- Gentoo update for OpenSSL
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
- Multiple vulnerabilities in IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data
- Multiple vulnerabilities in IBM Cognos Transformer
- Multiple vulnerabilities in IBM Cognos Analytics
- openEuler 20.03 LTS SP1 update for nodejs
- openEuler 22.03 LTS update for nodejs
- openEuler 22.03 LTS SP1 update for nodejs
- openEuler 22.03 LTS SP2 update for nodejs
- openEuler 22.03 LTS SP3 update for nodejs
- openEuler 22.03 LTS SP2 update for shim
- openEuler 20.03 LTS SP1 update for shim
- openEuler 22.03 LTS update for shim
- openEuler 22.03 LTS SP1 update for shim
- openEuler update for edk2
- openEuler 20.03 LTS SP4 update for nodejs
- Resource exhaustion in NX-OS Firmware used by IBM c-type SAN directors and switches
- openEuler update for openssl
- Multiple vulnerabilities in IBM Storage Protect for Virtual Environments: Data Protection for VMware
- Multiple vulnerabilities in IBM Storage Protect Client
- Multiple vulnerabilities in Siemens Telecontrol Server Basic
- Multiple vulnerabilities in IBM Workload Automation
- Resource exhaustion in IBM FOS firmware
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Siemens SCALANCE XM-400/XR-500
- Multiple vulnerabilities in Dell Secured Component Verification (SCV)
- Multiple vulnerabilities in Dell ThinOS
- Junos OS Evolved update for OpenSSL
- Multiple vulnerabilities in Dell Data Lakehouse System Software
- Multiple vulnerabilities in Dell Pair
- Multiple vulnerabilities in Dell ObjectScale
- IBM InfoSphere Master Data Management update for OpenSSL
- Multiple vulnerabilities in IBM Cloud Pak System
- Multiple vulnerabilities in IBM Event Streams
- Amazon Linux AMI update for openssl
- Multiple vulnerabilities in IBM Events Operator
- Multiple vulnerabilities in Dell PowerProtect Data Manager
- Multiple vulnerabilities in Dell NetWorker and NetWorker Management Console
- Dell NetWorker update for OpenSSL
- Ubuntu update for edk2
- Ubuntu update for edk2