Oracle alert ELSA-2021-3798 (openssl)
From: | Errata Announcements for Oracle Linux <el-errata@oss.oracle.com> | |
To: | el-errata@oss.oracle.com | |
Subject: | [El-errata] ELSA-2021-3798 Moderate: Oracle Linux 7 openssl security update (aarch64) | |
Date: | Wed, 13 Oct 2021 07:56:32 -0700 | |
Message-ID: | <6166f3a0.FO7gdv0h/o6SbVFk%keshav.sharma@oracle.com> |
Oracle Linux Security Advisory ELSA-2021-3798 http://linux.oracle.com/errata/ELSA-2021-3798.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: openssl-1.0.2k-22.el7_9.aarch64.rpm openssl-devel-1.0.2k-22.el7_9.aarch64.rpm openssl-libs-1.0.2k-22.el7_9.aarch64.rpm openssl-perl-1.0.2k-22.el7_9.aarch64.rpm openssl-static-1.0.2k-22.el7_9.aarch64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/openssl-1.0.2k-22... Related CVEs: CVE-2021-23840 CVE-2021-23841 Description of changes: [1.0.2k-22] - fix CVE-2021-23841 openssl: NULL pointer dereference in X509_issuer_and_serial_hash() - fix CVE-2021-23840 openssl: integer overflow in CipherUpdate - Resolves: rhbz#1932132, rhbz#1932126 _______________________________________________ El-errata mailing list El-errata@oss.oracle.com https://oss.oracle.com/mailman/listinfo/el-errata