Security update: openssl 4.0.2 RPM and DEB packages released

openssl 4.0.2 has been added to the CodeIT repository. The packages are built for RHEL, CentOS, AlmaLinux, Rocky Linux and Oracle Linux 7, 8, 9 and 10, and for Ubuntu 22.04 and 24.04.

RedHat FIPS patches removed as per upstream, we now have stock FIPS from OpenSSL to avoid broken web servers.

This update fixes security vulnerabilities. Upgrading is recommended.

Major changes:

  • OpenSSL 4.0.2 is a security patch release. The most severe CVE fixed in this release is Moderate.
  • This release incorporates the following bug fixes and mitigations:
  • Fixed checking of authentication tags for empty ciphertexts for AEAD ciphers in CCM cipher mode.

Fixed vulnerabilities:

  • Fixed QUIC server being able to trigger double free when processing `INITIAL` packet. (CVE-2026-18798)
  • Fixed heap buffer overflow in CMS key unwrapping. (CVE-2026-63072)
  • Fixed invalid pointer dereference in CMP server via crafted `protectionAlg`. (CVE-2026-63076)
  • Fixed unbounded memory growth in QUIC server incoming channel queue. (CVE-2026-14456)
  • Fixed RPK server signature algorithm selection being able to dereference a missing certificate. (CVE-2026-14457)
  • Fixed excessive memory use buffering DTLS records for a future epoch. (CVE-2026-54874)
  • Fixed client-side memory leak in OCSP response checking. (CVE-2026-54876)
  • Fixed untrusted Sender DN being used as a format string in CMP response validation. (CVE-2026-63073)
  • Fixed CMP indefinite cache growth of `extraCerts`. (CVE-2026-63074)
  • Fixed QUIC ACK-only packet retention being able to cause memory exhaustion. (CVE-2026-63075)
  • Fixed possibility of AEAD forgeries with empty ciphertext when using `EVP_Cipher()`. (CVE-2026-75803)

The libraries with QUIC support are still shipped as a separate, non-conflicting openssl-quic-libs package, with its own .so.81.4 suffix, so that they cannot clash with the official .so.X.

Leave a Reply

Your email address will not be published. Required fields are marked *