Resource exhaustion in OpenSSL - CVE-2023-0464

 

Resource exhaustion in OpenSSL - CVE-2023-0464

Published: March 22, 2023 / Updated: May 30, 2023


Vulnerability identifier: #VU73960
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-0464
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when verifying X.509 certificate chains that include policy constraints. A remote attacker can create a specially crafted certificate to trigger resource exhaustion and perform a denial of service (DoS) attack.


Affected software

OpenSSL
Isolation Segment
VMware Tanzu Application Service for VMs
Data Lakehouse
cert-manager Operator for Red Hat OpenShift
Dell Secure Connect Gateway
IBM Rational Build Forge
IBM QRadar WinCollect Agent
NetWorker
IBM Spectrum Conductor
IBM Cloud Transformation Advisor
IBM Tivoli Netcool System Service Monitors/Application Service Monitors
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
IBM Spectrum Control
IBM Safer Payments
IBM Spectrum Symphony
IBM Rational ClearCase
IBM Rational ClearQuest
IBM Spectrum Protect Plus
InfoSphere Master Data Management
PowerProtect Data Manager
Amazon Linux AMI
Oracle Linux
Debian Linux
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
Legacy Module
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server 12 SP4 LTSS
Ubuntu
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Junos OS Evolved
Cisco NX-OS
Dell Data Protection Central
Dell EMC PowerProtect Data Protection
Telemetry Dashboard
Liquidware
Citrix Workspace App
Webex App VDI
HP-UX OpenSSL
cflinuxfs3
Pair
ObjectScale
Storage Defender – Data Protect
Secured Component Verification (SCV)
Enterprise SONiC
IBM Cloud Pak for Watson AIOps
Platform Automation Toolkit
DB2 on Cloud Pak for Data
DB2 Warehouse on Cloud Pak for Data
Events Operator
MobileFirst Platform
Storage Protect Client
Storage Protect for Virtual Environments: Data Protection for VMware
IBM Workload Automation
Cognos Transformer
EMC Cloud Tiering Appliance
Dell PowerProtect Cyber Recovery
API Gateway
JBoss Core Services
API Manager
OpenShift sandboxed containers
OpenShift Data Foundation (formerly OpenShift Container Storage)
Oracle VM VirtualBox
VMware Tanzu Operations Manager
Argo CD
Network Observability plugin for the Openshift Console
Red Hat OpenShift Container Platform
IBM Watson Explorer Foundational Components
IBM Watson Explorer Deep Analytics Edition Foundational Components
VMware Horizon Client
JBoss Web Server
Zimbra Collaboration
IBM InfoSphere Information Server
Cisco Jabber
Cisco Webex Meetings
libssl1.0.0 (Ubuntu package)
libssl-doc (Ubuntu package)
openssl (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
openssl-doc
libopenssl0_9_8-hmac
openssl
libopenssl0_9_8
libopenssl0_9_8-32bit
libopenssl0_9_8-hmac-32bit
libopenssl0_9_8-debuginfo
libopenssl0_9_8-debuginfo-32bit
compat-openssl098-debugsource
jbcs-httpd24-openssl-chil (Red Hat package)
libopenssl1_0_0-32bit
openssl1-doc
libopenssl1_0_0
libopenssl1-devel
openssl1
libopenssl1_0_0-debuginfo
openssl-debuginfo
libopenssl1_0_0-debuginfo-32bit
openssl-debugsource
libopenssl-devel
libopenssl1_0_0-hmac
libopenssl1_0_0-hmac-32bit
openssl-1_0_0
libopenssl-1_0_0-devel-32bit
openssl-1_0_0-doc
libopenssl-1_0_0-devel
openssl-1_0_0-debugsource
openssl-1_0_0-debuginfo
openssl1.0 (Ubuntu package)
libopenssl1_0_0-steam-debuginfo
libopenssl1_0_0-steam
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
libopenssl1_0_0-32bit-debuginfo
openssl-1_0_0-cavs-debuginfo
libopenssl10
libopenssl10-debuginfo
openssl-1_0_0-cavs
openssl-1_1-debugsource
libopenssl1_1-hmac
openssl-1_1
libopenssl1_1
libopenssl1_1-debuginfo
openssl-1_1-debuginfo
libopenssl-1_1-devel
libopenssl1_1-32bit-debuginfo
libopenssl1_1-32bit
libopenssl-1_1-devel-32bit
libopenssl1_1-hmac-32bit
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-help
openssl-devel
openssl-libs
libssl1.1 (Ubuntu package)
openssl (Debian package)
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
openssl-3
libopenssl3-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
libopenssl3-32bit-debuginfo
openssl-3-doc
openssl-3-debuginfo
libopenssl3
openssl-3-debugsource
libopenssl-3-devel
libssl3 (Ubuntu package)
openssl (Red Hat package)
dev-libs/openssl
npm
v8-devel
jbcs-httpd24-curl (Red Hat package)
jws5-tomcat (Red Hat package)
nodejs-docs
nodejs-debuginfo
nodejs-devel
nodejs-libs
nodejs-full-i18n
nodejs-debugsource
nodejs
shim-debugsource
shim-debuginfo
shim
edk2 (Ubuntu package)
edk2
edk2-debuginfo
edk2-devel
edk2-debugsource
edk2-help
python3-edk2-devel
edk2-aarch64
edk2-ovmf
SINEC INS
Dell G15 5511
Alienware m15 R6
XPS 8960
FOS Firmware
IBM Cloud Pak System
TeleControl Server Basic
Event Streams
NetWorker Management Console
SCALANCE XR552-12M
SCALANCE XR528-6M
SCALANCE XR526-8C
SCALANCE XR524-8C
SCALANCE XM416-4C
SCALANCE XM408-8C
SCALANCE XM408-4C
IBM Security Verify Access
IBM CICS TX Advanced
IBM Cognos Analytics

How to mitigate CVE-2023-0464

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.2zh, 1.1.1u, 3.0.9, 3.1.1
API Gateway - addressed in versions August 2023, May 2023
API Manager - addressed in versions August 2023, May 2023
Data Lakehouse - update to 1.1.0.0
Telemetry Dashboard - update to 1.1.0.6 on Thin OS 2405
OpenShift sandboxed containers - update to 1.4.1
cert-manager Operator for Red Hat OpenShift - update to 1.10.3
Argo CD - update to 2.6.8
Red Hat OpenShift Container Platform - addressed in versions 4.12.23, 4.13.5, 4.13.6
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.1
JBoss Web Server - update to 5.7.7
Dell Secure Connect Gateway - update to 5.16
Oracle VM VirtualBox - addressed in versions 6.1.46, 7.0.10
Liquidware - update to 6.7.0.2.2 on Thin OS 2405
IBM Rational Build Forge - update to 8.0.0.25
Zimbra Collaboration - addressed in versions 8.8.15 Patch 41, 9.0.0 Patch 34, 10.0.2
IBM QRadar WinCollect Agent - update to 10.1.6
IBM Watson Explorer Foundational Components - update to 11.0.2.16
IBM InfoSphere Information Server - update to 11.7.1.4 Service pack 2
IBM Watson Explorer Deep Analytics Edition Foundational Components - update to 12.0.3.12
Cisco Jabber - update to 14.3.0.308378.11 on Thin OS 2405
NetWorker - addressed in versions 19.10.0.0, 19.11.0.3, 19.11.0.6, 19.12.0.0, 19.12.0.2
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
Citrix Workspace App - update to 24.2.0.65.17 on Thin OS 2405
Webex App VDI - update to 44.2.0.28744.1 on Thin OS 2405
Cisco Webex Meetings - update to 44.2.0.76.2 on Thin OS 2405
VMware Horizon Client - update to 2312.1.8.12.1.5 on Thin OS 2405
libssl1.0.0 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.0.2n-1ubuntu5.12
libssl-doc (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22, 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
HP-UX OpenSSL - update to A.01.01.01w.001
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
openssl-doc - addressed in versions 0.9.8j-0.106.63.1, 1.0.2j-60.89.1
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.63.1
openssl - addressed in versions 0.9.8j-0.106.63.1, 1.0.2j-60.89.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.63.1, 0.9.8j-106.45.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.63.1, 0.9.8j-106.45.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.63.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.45.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.45.1
compat-openssl098-debugsource - update to 0.9.8j-106.45.1
cflinuxfs3 - update to 0.364.0
SINEC INS - update to 1.0 SP2 Update 2
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.59.1, 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl1-doc - update to 1.0.1g-0.58.59.1
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.59.1, 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl1-devel - update to 1.0.1g-0.58.59.1
openssl1 - update to 1.0.1g-0.58.59.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-debuginfo - update to 1.0.2j-60.89.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1
openssl-debugsource - update to 1.0.2j-60.89.1
libopenssl-devel - update to 1.0.2j-60.89.1
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.89.1, 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl-1_0_0-devel-32bit - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0-doc - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.69.1, 1.0.2p-150000.3.70.1
openssl1.0 (Ubuntu package) - update to 1.0.2n-1ubuntu5.12
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.70.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.70.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.70.1
libopenssl10 - update to 1.0.2p-150000.3.70.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.70.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.70.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-hmac - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
openssl-1_1 - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1 - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl-1_1-devel - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-32bit - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150100.14.45.1, 1.1.1d-2.78.1, 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.78.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.62.1, 1.1.1l-150400.7.31.2
openssl-debuginfo - update to 1.1.1f-23
openssl-debugsource - update to 1.1.1f-23
openssl-help - update to 1.1.1f-23
openssl-devel - update to 1.1.1f-23
openssl-libs - update to 1.1.1f-23
openssl - update to 1.1.1f-23
libssl1.1 (Ubuntu package) - addressed in versions 1.1.1f-1ubuntu2.18, 1.1.1-1ubuntu2.1~18.04.22
openssl (Debian package) - update to 1.1.1n-0+deb11u5
Pair - update to 1.2.3
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-16.redhat_16.el7jws, 1.2.31-16.redhat_16.el8jws, 1.2.31-16.redhat_16.el9jws
Network Observability plugin for the Openshift Console - update to 1.3.0
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.1
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
Secured Component Verification (SCV) - update to 1.92.0
XPS 8960 - update to 2.3.0
IBM Cloud Pak System - addressed in versions 2.3.4.1, 2.3.5.0
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
IBM Spectrum Conductor - update to 2.5.1 FP2
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
VMware Tanzu Operations Manager - addressed in versions 2.10.57, 3.0.8
openssl-3 - update to 3.0.1-150400.4.20.1
libopenssl3-debuginfo - update to 3.0.1-150400.4.20.1
libopenssl3-32bit - update to 3.0.1-150400.4.20.1
libopenssl-3-devel-32bit - update to 3.0.1-150400.4.20.1
libopenssl3-32bit-debuginfo - update to 3.0.1-150400.4.20.1
openssl-3-doc - update to 3.0.1-150400.4.20.1
openssl-3-debuginfo - update to 3.0.1-150400.4.20.1
libopenssl3 - update to 3.0.1-150400.4.20.1
openssl-3-debugsource - update to 3.0.1-150400.4.20.1
libopenssl-3-devel - update to 3.0.1-150400.4.20.1
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.9, 3.0.5-2ubuntu2.2, 3.0.8-1ubuntu1.1
openssl (Red Hat package) - update to 3.0.7-16.el9_2
openssl - update to 3.0.8-1
dev-libs/openssl - update to 3.0.10
TeleControl Server Basic - update to 3.1.2
IBM Cloud Transformation Advisor - update to 3.5.2
IBM Tivoli Netcool System Service Monitors/Application Service Monitors - update to 4.0.1 SP11
Enterprise SONiC - update to 4.1.2
IBM Cloud Pak for Watson AIOps - update to 4.2.1
Platform Automation Toolkit - addressed in versions 4.4.31, 5.0.24, 5.1.1
DB2 on Cloud Pak for Data - update to 4.8.2
DB2 Warehouse on Cloud Pak for Data - update to 4.8.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.2
Events Operator - update to 5.1.0
IBM Spectrum Control - update to 5.4.10.2
IBM Safer Payments - addressed in versions 6.3.1.05, 6.4.2.04, 6.5.0.02
SCALANCE XR552-12M - update to 6.6.1
SCALANCE XR528-6M - update to 6.6.1
SCALANCE XR526-8C - update to 6.6.1
SCALANCE XR524-8C - update to 6.6.1
SCALANCE XM416-4C - update to 6.6.1
SCALANCE XM408-8C - update to 6.6.1
SCALANCE XM408-4C - update to 6.6.1
npm - addressed in versions 6.14.16-1.12.22.11.7, 6.14.16-1.12.22.11.9
IBM Spectrum Symphony - update to 7.3.2 Fix 601711
v8-devel - addressed in versions 7.8.279.23-1.12.22.11.7, 7.8.279.23-1.12.22.11.9
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202307260922
Storage Protect Client - update to 8.1.22.0
Storage Protect for Virtual Environments: Data Protection for VMware - update to 8.1.22.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
IBM Rational ClearCase - addressed in versions 9.0.2.8, 9.1.0.5
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-19.redhat_00017.1.el7jws, 9.0.62-19.redhat_00017.1.el8jws, 9.0.62-19.redhat_00017.1.el9jws
FOS Firmware - addressed in versions 9.2.0b, 9.2.1
Cisco NX-OS - update to 9.4(1a)
IBM Workload Automation - addressed in versions 9.5.0.7, 10.1.0.4
IBM Security Verify Access - update to 10.0.7.0
IBM CICS TX Advanced - update to 10.1.0.0 ifix18
IBM Spectrum Protect Plus - update to 10.1.15
Cognos Transformer - update to 11.1.7 Fix Pack 8
IBM Cognos Analytics - addressed in versions 11.1.7 Fix Pack 8, 11.2.4 FP3, 12.0.2
Event Streams - update to 11.5.1
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
nodejs-docs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debuginfo - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-devel - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-libs - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-full-i18n - addressed in versions 12.22.11-7, 12.22.11-9
nodejs-debugsource - addressed in versions 12.22.11-7, 12.22.11-9
nodejs - addressed in versions 12.22.11-7, 12.22.11-9
EMC Cloud Tiering Appliance - update to 13.2.0.2.22
shim-debugsource - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15-28
shim-debuginfo - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15-28
shim - addressed in versions 15.4-13, 15.6-16, 15.6-17, 15-28
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
Dell PowerProtect Cyber Recovery - update to 19.14.0.1
PowerProtect Data Manager - update to 19.19.0-15
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2 - update to 202002-18
edk2-debuginfo - update to 202002-18
edk2-devel - update to 202002-18
edk2-debugsource - update to 202002-18
edk2-help - update to 202002-18
python3-edk2-devel - update to 202002-18
edk2-aarch64 - update to 202002-18
edk2-ovmf - update to 202002-18

External References

Related Security Bulletins