Resource management error in OpenSSL - CVE-2023-3446

 

Resource management error in OpenSSL - CVE-2023-3446

Published: July 20, 2023 / Updated: August 2, 2023


Vulnerability identifier: #VU78463
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-3446
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper management of internal resources within the DH_check(), DH_check_ex() and EVP_PKEY_param_check() function when processing a DH key or DH parameters. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


Affected software

OpenSSL
Amazon Linux AMI
Gentoo Linux
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Server 11
SUSE Linux Enterprise Software Development Kit 12
SUSE CaaS Platform
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Fedora
SUSE Enterprise Storage
IBM i
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE
Legacy Module
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
Slackware Linux
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Basesystem Module
openSUSE Leap
openEuler
Junos OS Evolved
Dell EMC PowerProtect Data Protection
Dell Data Protection Central
Cognos Dashboards on Cloud Pak for Data
webMethods Managed File Transfer
ObjectScale
Storage Defender – Data Protect
IBM Planning Analytics Workspace
Storage Copy Data Management
IBM OS Image for Red Hat Linux Systems
Enterprise SONiC
Dell Policy Manager for Secure Connect Gateway (SCG)
Storage Ceph
Storage Protect Client
Storage Virtualize
IBM supplied MQ Advanced container images
IBM Sterling Order Management
SmartFabric OS10
Cognos Transformer
Dell PowerProtect Cyber Recovery
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
Red Hat OpenShift Builds
Data Lakehouse
Migration Toolkit for Runtimes
Service Telemetry Framework
Cryostat
IBM Cloud Pak for Data System
IBM Cloud Transformation Advisor
Red Hat Advanced Cluster Management for Kubernetes
Red Hat Advanced Cluster Security for Kubernetes
OpenShift Logging
IBM Rational Build Forge
Tenable Nessus
Multicluster GlobalHub
Sensor Proxy
Service Interconnect
IBM MQ Operator
Ansible Automation Platform
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
Red Hat OpenShift Dev Spaces
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
EasyApache
App Connect Enterprise Certified Container
IBM Spectrum Control
Red Hat Migration Toolkit for Applications
Session Smart Router
IBM Maximo Application Suite
IBM Rational ClearQuest
IBM Rational ClearCase
IBM Security Verify Governance
IBM Power Hardware Management Console (HMC)
InfoSphere Master Data Management
Red Hat OpenStack
NetWorker
Juniper Cloud Native Router
Voice Gateway
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
QRadar Suite
Splunk Enterprise
JBoss Web Server
IBM Qradar SIEM
Nessus Agent
Event Streams
TeleControl Server Basic
NetWorker Management Console
Red Hat Single Sign-On
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssl (Ubuntu package)
libssl1.0.0 (Ubuntu package)
libssl1.1 (Ubuntu package)
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
libopenssl0_9_8-hmac
libopenssl0_9_8-hmac-32bit
openssl
libopenssl0_9_8-32bit
libopenssl0_9_8
openssl-doc
libopenssl0_9_8-debuginfo
compat-openssl098-debugsource
libopenssl0_9_8-debuginfo-32bit
jbcs-httpd24-openssl-chil (Red Hat package)
openssl1-doc
libopenssl1-devel
libopenssl1_0_0-32bit
libopenssl1_0_0
openssl1
libopenssl1_0_0-hmac
openssl-debugsource
libopenssl1_0_0-debuginfo
libopenssl1_0_0-debuginfo-32bit
libopenssl-devel
openssl-debuginfo
libopenssl1_0_0-hmac-32bit
openssl-1_0_0
openssl-1_0_0-doc
libopenssl-1_0_0-devel-32bit
libopenssl-1_0_0-devel
openssl-1_0_0-debuginfo
openssl-1_0_0-debugsource
libopenssl1_0_0-32bit-debuginfo
libopenssl1_0_0-steam-32bit-debuginfo
libopenssl1_0_0-steam-32bit
openssl-1_0_0-cavs-debuginfo
libopenssl1_0_0-steam
openssl-1_0_0-cavs
libopenssl1_0_0-steam-debuginfo
libopenssl10
libopenssl10-debuginfo
libopenssl1_1-32bit
libopenssl1_1-32bit-debuginfo
libopenssl-1_1-devel-32bit
libopenssl1_1-hmac-32bit
libopenssl-1_1-devel
libopenssl1_1
openssl-1_1
openssl-1_1-debugsource
libopenssl1_1-debuginfo
libopenssl1_1-hmac
openssl-1_1-debuginfo
libopenssl1_1-debuginfo-32bit
openssl-1_1-doc
openssl-devel
openssl-libs
openssl-help
openssl11
openssl-perl
openssl (Red Hat package)
libopenssl-1_1-devel-64bit
libopenssl1_1-64bit-debuginfo
libopenssl1_1-64bit
libopenssl1_1-hmac-64bit
openssl1.1
openssl1.1-devel
openssl1.1-doc
openssl-solibs
jws5-tomcat-native (Red Hat package)
jbcs-httpd24-mod_proxy_cluster (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
libssl3 (Ubuntu package)
openssl-fips-provider (Red Hat package)
libopenssl-3-devel-64bit
openssl-3-debugsource
libopenssl3-32bit-debuginfo
openssl-3-doc
libopenssl3-64bit-debuginfo
libopenssl-3-devel
openssl-3
libopenssl3-debuginfo
libopenssl3-32bit
libopenssl-3-devel-32bit
libopenssl3
libopenssl3-64bit
openssl-3-debuginfo
dev-libs/openssl
jbcs-httpd24-curl (Red Hat package)
jws5-tomcat (Red Hat package)
shim
shim-debuginfo
shim-debugsource
edk2 (Ubuntu package)
edk2-debugsource
edk2-devel
python3-edk2-devel
edk2-aarch64
edk2-debuginfo
edk2
edk2-ovmf
edk2-help
edk2 (Red Hat package)
edk2-tools-doc
Splunk Universal Forwarder
IBM Storage Scale System
IBM App Connect Enterprise
IBM CICS TX Advanced
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Dell G15 5511
Alienware m15 R6
XPS 8960
FOS Firmware
Junos cRPD
IBM Cloud Pak System
JBoss Core Services
SIMATIC MV500
RecoverPoint for VMs
Dell EMC VxRail Appliance
IBM Security Verify Access
IBM InfoSphere Information Server

How to mitigate CVE-2023-3446

Install update from vendor's website.

OpenSSL - addressed in versions 1.0.2zi, 1.1.1v, 3.0.10, 3.1.2
Dell EMC PowerProtect Data Protection - update to 2.7.8
Red Hat OpenShift Serverless - addressed in versions 1.31.1, 1.32.0
Red Hat OpenShift Builds - update to 1.0.1
Data Lakehouse - update to 1.1.0.0
Voice Gateway - update to 1.0.8.12
Migration Toolkit for Runtimes - addressed in versions 1.2.4, 1.2.5
Service Telemetry Framework - update to 1.5.4
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3, 1.8.4
QRadar Suite - update to 1.10.18.0
IBM Cloud Pak for Data System - update to 8.10.25.04.SP2
IBM Cloud Transformation Advisor - update to 3.10.2
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.8.5, 2.9.2, 2.9.3, 2.10.5
Red Hat Advanced Cluster Security for Kubernetes - addressed in versions 3.74.8, 4.1.6, 4.2.4
Red Hat OpenShift Container Platform - addressed in versions 4.11.57, 4.12.53, 4.13.45, 4.14.32, 4.14.33, 4.17.0
JBoss Web Server - update to 5.7.7
OpenShift Logging - update to 5.7.10
IBM Qradar SIEM - update to 7.5.0 Update Pack 8
Red Hat Single Sign-On - update to 7.6.6
IBM Rational Build Forge - update to 8.0.0.25
Splunk Universal Forwarder - addressed in versions 9.0.7, 9.1.2
Splunk Enterprise - addressed in versions 9.0.7, 9.1.2
Nessus Agent - update to 10.4.3
Tenable Nessus - update to 10.5.4
Event Streams - update to 11.5.1
IBM App Connect Enterprise - addressed in versions 11.0.0.23, 12.0.10.0
Junos OS Evolved - addressed in versions 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S2-EVO, 22.4R3-S1-EVO, 23.2R2-EVO, 23.4R1-EVO
openssl (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.20
libssl1.0.0 (Ubuntu package) - update to Ubuntu Pro
libssl1.1 (Ubuntu package) - addressed in versions Ubuntu Pro, 1.1.1f-1ubuntu2.20
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-34.el7jbcs, 0.4.10-34.el8jbcs
libopenssl0_9_8-hmac - update to 0.9.8j-0.106.77.1
libopenssl0_9_8-hmac-32bit - update to 0.9.8j-0.106.77.1
openssl - addressed in versions 0.9.8j-0.106.77.1, 1.0.2j-60.101.1
libopenssl0_9_8-32bit - addressed in versions 0.9.8j-0.106.77.1, 0.9.8j-106.58.1
libopenssl0_9_8 - addressed in versions 0.9.8j-0.106.77.1, 0.9.8j-106.58.1
openssl-doc - addressed in versions 0.9.8j-0.106.77.1, 1.0.2j-60.101.1
libopenssl0_9_8-debuginfo - update to 0.9.8j-106.58.1
compat-openssl098-debugsource - update to 0.9.8j-106.58.1
libopenssl0_9_8-debuginfo-32bit - update to 0.9.8j-106.58.1
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-19.el7jbcs, 1.0.0-19.el8jbcs
openssl1-doc - update to 1.0.1g-0.58.73.1
libopenssl1-devel - update to 1.0.1g-0.58.73.1
libopenssl1_0_0-32bit - addressed in versions 1.0.1g-0.58.73.1, 1.0.2j-60.101.1, 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
libopenssl1_0_0 - addressed in versions 1.0.1g-0.58.73.1, 1.0.2j-60.101.1, 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
openssl1 - update to 1.0.1g-0.58.73.1
Multicluster GlobalHub - update to 1.0.2
libopenssl1_0_0-hmac - addressed in versions 1.0.2j-60.101.1, 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
openssl-debugsource - update to 1.0.2j-60.101.1
libopenssl1_0_0-debuginfo - addressed in versions 1.0.2j-60.101.1, 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
libopenssl1_0_0-debuginfo-32bit - addressed in versions 1.0.2j-60.101.1, 1.0.2p-3.81.1
libopenssl-devel - update to 1.0.2j-60.101.1
openssl-debuginfo - update to 1.0.2j-60.101.1
libopenssl1_0_0-hmac-32bit - addressed in versions 1.0.2j-60.101.1, 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
openssl-1_0_0 - addressed in versions 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
openssl-1_0_0-doc - addressed in versions 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
libopenssl-1_0_0-devel-32bit - addressed in versions 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
libopenssl-1_0_0-devel - addressed in versions 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
openssl-1_0_0-debuginfo - addressed in versions 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
openssl-1_0_0-debugsource - addressed in versions 1.0.2p-3.81.1, 1.0.2p-150000.3.82.1
libopenssl1_0_0-32bit-debuginfo - update to 1.0.2p-150000.3.82.1
libopenssl1_0_0-steam-32bit-debuginfo - update to 1.0.2p-150000.3.82.1
libopenssl1_0_0-steam-32bit - update to 1.0.2p-150000.3.82.1
openssl-1_0_0-cavs-debuginfo - update to 1.0.2p-150000.3.82.1
libopenssl1_0_0-steam - update to 1.0.2p-150000.3.82.1
openssl-1_0_0-cavs - update to 1.0.2p-150000.3.82.1
libopenssl1_0_0-steam-debuginfo - update to 1.0.2p-150000.3.82.1
libopenssl10 - update to 1.0.2p-150000.3.82.1
libopenssl10-debuginfo - update to 1.0.2p-150000.3.82.1
Sensor Proxy - update to 1.0.8
libopenssl1_1-32bit - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-32bit-debuginfo - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl-1_1-devel-32bit - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-hmac-32bit - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl-1_1-devel - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1 - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
openssl-1_1 - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
openssl-1_1-debugsource - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-debuginfo - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-hmac - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
openssl-1_1-debuginfo - addressed in versions 1.1.0i-150100.14.59.1, 1.1.1d-2.92.1, 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-debuginfo-32bit - update to 1.1.1d-2.92.1
openssl-1_1-doc - addressed in versions 1.1.1d-150200.11.72.1, 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
openssl - addressed in versions 1.1.1f-26, 1.1.1f-27
openssl-devel - addressed in versions 1.1.1f-26, 1.1.1f-27
openssl-libs - addressed in versions 1.1.1f-26, 1.1.1f-27
openssl-debuginfo - addressed in versions 1.1.1f-26, 1.1.1f-27
openssl-debugsource - addressed in versions 1.1.1f-26, 1.1.1f-27
openssl-help - addressed in versions 1.1.1f-26, 1.1.1f-27
openssl11 - update to 1.1.1k-6.el7
openssl - addressed in versions 1.1.1k-12.0.1, 3.0.12-2
openssl-perl - addressed in versions 1.1.1k-12.0.1, 3.0.12-2
openssl-libs - addressed in versions 1.1.1k-12.0.1, 3.0.12-2
openssl-devel - addressed in versions 1.1.1k-12.0.1, 3.0.12-2
openssl (Red Hat package) - addressed in versions 1.1.1k-12.el8_6, 1.1.1k-12.el8_8, 1.1.1k-12.el8_9, 3.0.7-27.el9
libopenssl-1_1-devel-64bit - addressed in versions 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-64bit-debuginfo - addressed in versions 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-64bit - addressed in versions 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
libopenssl1_1-hmac-64bit - addressed in versions 1.1.1l-150400.7.48.1, 1.1.1l-150500.17.9.1
openssl1.1 - update to 1.1.1q-11
openssl1.1-devel - update to 1.1.1q-11
openssl1.1-doc - update to 1.1.1q-11
openssl-solibs - update to 1.1.1v
openssl - update to 1.1.1v
jws5-tomcat-native (Red Hat package) - addressed in versions 1.2.31-16.redhat_16.el7jws, 1.2.31-16.redhat_16.el8jws, 1.2.31-16.redhat_16.el9jws
OpenShift API for Data Protection (OADP) - update to 1.3.2
jbcs-httpd24-mod_proxy_cluster (Red Hat package) - addressed in versions 1.3.19-7.el7jbcs, 1.3.19-7.el8jbcs
ObjectScale - update to 1.4.0
Storage Defender – Data Protect - update to 1.4.1
Service Interconnect - update to 1.5.4
Network Observability plugin for the Openshift Console - update to 1.6.0
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-103.el7jbcs, 1.6.1-103.el8jbcs
Red Hat OpenShift GitOps - addressed in versions 1.12.5, 1.13.1
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.19-32.el7jbcs, 1.15.19-32.el8jbcs
Dell G15 5511 - update to 1.26.0
Alienware m15 R6 - update to 1.27.0
IBM MQ Operator - addressed in versions 2.0.18, 2.4.7, 3.0.1
IBM Planning Analytics Workspace - addressed in versions 2.0.95, 2.1.2
Storage Copy Data Management - update to 2.2.23.0
XPS 8960 - update to 2.3.0
IBM Cloud Pak System - update to 2.3.4.1
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.4.24-2.el7jbcs, 2.4.24-2.el8jbcs
JBoss Core Services - update to 2.4.57 SP2
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.57-7.el7jbcs, 2.4.57-7.el8jbcs
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.3-32.el7jbcs, 2.9.3-32.el8jbcs
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-394
libssl3 (Ubuntu package) - addressed in versions 3.0.2-0ubuntu1.12, 3.0.8-1ubuntu1.4, 3.0.10-1ubuntu2.1
openssl-fips-provider (Red Hat package) - update to 3.0.7-2.el9
openssl - update to 3.0.8-1
libopenssl-3-devel-64bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3-debugsource - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-32bit-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3-doc - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-64bit-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl-3-devel - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3 - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-32bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl-3-devel-32bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3 - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
libopenssl3-64bit - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
openssl-3-debuginfo - addressed in versions 3.0.8-150400.4.31.2, 3.0.8-150500.5.8.1
dev-libs/openssl - update to 3.0.10
openssl-doc - update to 3.0.12-2
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.1.0
TeleControl Server Basic - update to 3.1.2
SIMATIC MV500 - update to 3.3.5
Red Hat OpenShift Dev Spaces - update to 3.16.0
IBM OS Image for Red Hat Linux Systems - update to 4.0.4.0
Enterprise SONiC - update to 4.1.2
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.7
OpenShift Virtualization - update to 4.14.6
EasyApache - update to 4 2023-8-9
App Connect Enterprise Certified Container - addressed in versions 5.0.15, 11.3.0
IBM Spectrum Control - update to 5.4.11
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.20
RecoverPoint for VMs - update to 6.0.SP1.P1
IBM Storage Scale System - addressed in versions 6.1.9.5, 6.2.2.0
Red Hat Migration Toolkit for Applications - addressed in versions 6.2.3, 7.0.3
Session Smart Router - addressed in versions 6.2.3-r2, 6.2.10, 6.3.7
Storage Ceph - update to 7.1
Dell EMC VxRail Appliance - update to 8.0.120
OpenShift Container Platform for Windows Containers - addressed in versions 8.1.3, 10.15.3
Storage Protect Client - update to 8.1.23.0
jbcs-httpd24-curl (Red Hat package) - addressed in versions 8.4.0-2.el7jbcs, 8.4.0-2.el8jbcs
Storage Virtualize - addressed in versions 8.7.0.3, 8.7.2.0
IBM Integrated Analytics System - update to 8.8.24.10.SP1
IBM Maximo Application Suite - addressed in versions 8.10.10, 8.11.7
IBM Rational ClearQuest - addressed in versions 9.0.2.8, 9.1.0.5, 10.0.3
jws5-tomcat (Red Hat package) - addressed in versions 9.0.62-19.redhat_00017.1.el7jws, 9.0.62-19.redhat_00017.1.el8jws, 9.0.62-19.redhat_00017.1.el9jws
IBM Rational ClearCase - addressed in versions 9.1.0.6, 10.0.1.1
FOS Firmware - addressed in versions 9.1.1d, 9.2.0b, 9.2.1
IBM supplied MQ Advanced container images - addressed in versions 9.3.0.15-r1, 9.3.3.3-r1, 9.3.4.1-r1
IBM Security Verify Governance - update to 10.0.2.0.4
IBM Security Verify Access - update to 10.0.7.0
IBM Sterling Order Management - update to 10.0.2403.1
IBM CICS TX Advanced - update to 10.1.0.0 ifix24
IBM Power Hardware Management Console (HMC) - addressed in versions 10.2.1040.0 SP2, 10.3.1060.0
SmartFabric OS10 - update to 10.5.6.1
Cognos Transformer - update to 11.1.7 Fix Pack 8
InfoSphere Master Data Management - addressed in versions 11.6.0.12 IF003, 12.0.0.0 IF006
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
shim - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15-29, 15-35
shim-debuginfo - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15-29, 15-35
shim-debugsource - addressed in versions 15.4-14, 15.6-17, 15.6-18, 15-29, 15-35
Red Hat OpenStack - addressed in versions 16.2, 17.1
NetWorker - addressed in versions 19.11.0.3, 19.12.0.0
NetWorker Management Console - addressed in versions 19.11.0.3, 19.12.0.0
Dell PowerProtect Cyber Recovery - update to 19.15.0.1
Juniper Cloud Native Router - update to 23.4R1
Junos cRPD - update to 23.4R1
edk2 (Ubuntu package) - addressed in versions 2022.02-3ubuntu0.22.04.4, 2022.02-3ubuntu0.22.04.5, 2024.02-2ubuntu0.6, 2024.02-2ubuntu0.7, 2025.02-3ubuntu2.2
edk2-debugsource - update to 202002-18
edk2-devel - update to 202002-18
python3-edk2-devel - update to 202002-18
edk2-aarch64 - update to 202002-18
edk2-debuginfo - update to 202002-18
edk2 - update to 202002-18
edk2-ovmf - update to 202002-18
edk2-help - update to 202002-18
edk2 (Red Hat package) - addressed in versions 20220126gitbb1bba3d77-4.el8_8.3, 20220126gitbb1bba3d77-6.el8_9.3, 20231122-6.el9
edk2-ovmf - update to 20220126gitbb1bba3d77-13.0.1
edk2-tools-doc - update to 20220126gitbb1bba3d77-13.0.1
edk2-aarch64 - update to 20220126gitbb1bba3d77-13.0.1

External References

Related Security Bulletins